{"api_version":"1","generated_at":"2026-07-23T12:11:45+00:00","cve":"CVE-2020-17480","urls":{"html":"https://cve.report/CVE-2020-17480","api":"https://cve.report/api/cve/CVE-2020-17480.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-17480","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-17480"},"summary":{"title":"CVE-2020-17480","description":"TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-08-10 20:15:00","updated_at":"2020-08-11 15:47:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes","name":"https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"TinyMCE | TinyMCE 5.1.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95","name":"https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95","refsource":"MISC","tags":["Exploit","Release Notes","Third Party Advisory"],"title":"Cross-site scripting vulnerability in TinyMCE · Advisory · tinymce/tinymce · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-17480","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-17480","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"17480","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tiny","cpe5":"tinymce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"17480","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tiny","cpe5":"tinymce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-17480","qid":"982665","title":"Nodejs (npm) Security Update for tinymce (GHSA-p7j5-4mwm-hv86)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-17480","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95","refsource":"MISC","name":"https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95"},{"url":"https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes","refsource":"MISC","name":"https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes"}]}},"nvd":{"publishedDate":"2020-08-10 20:15:00","lastModifiedDate":"2020-08-11 15:47:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*","versionEndExcluding":"4.9.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.1.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"17480","Ordinal":"178889","Title":"CVE-2020-17480","CVE":"CVE-2020-17480","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"17480","Ordinal":"1","NoteData":"TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"17480","Ordinal":"2","NoteData":"2020-08-10","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"17480","Ordinal":"3","NoteData":"2020-08-10","Type":"Other","Title":"Modified"}]}}}