Known Vulnerabilities for products from Tiny

Listed below are 19 of the newest known vulnerabilities associated with the vendor "Tiny".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-47762 json TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged... Not Provided 2026-05-28 2026-05-28
CVE-2026-47761 json TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the med... Not Provided 2026-05-28 2026-05-28
CVE-2026-47760 json TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by impro... Not Provided 2026-05-28 2026-05-28
CVE-2026-47759 json TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsani... Not Provided 2026-05-28 2026-05-28
CVE-2026-46740 json Not Provided 2026-05-26 2026-05-28
CVE-2026-46720 json Not Provided 2026-05-17 2026-05-18
CVE-2026-46209 json Not Provided 2026-05-28 2026-05-28
CVE-2026-43115 json Not Provided 2026-05-06 2026-05-07
CVE-2026-7010 json Not Provided 2026-05-11 2026-05-12
CVE-2025-67520 json Not Provided 2025-12-09 2026-04-27
CVE-2025-39946 json Not Provided 2025-10-04 2026-04-02
CVE-2024-47635 json Not Provided 2024-10-05 2026-04-23
CVE-2024-24701 json Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based con... Not Provided 2024-02-29 2026-04-28
CVE-2024-21911 json 6.1 - MEDIUM 2024-01-03 2024-01-08
CVE-2024-21910 json 6.1 - MEDIUM 2024-01-03 2024-01-08
CVE-2024-21908 json 6.1 - MEDIUM 2024-01-03 2024-01-08
CVE-2023-45819 json TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notifica... 6.1 - MEDIUM 2023-10-19 2023-10-26
CVE-2023-45818 json TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’... 6.1 - MEDIUM 2023-10-19 2023-10-26
CVE-2022-23494 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.1 - MEDIUM 2022-12-08 2022-12-12
CVE-2021-23562 json This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker... 8.8 - HIGH 2021-12-03 2021-12-07

Known software with vulnerabilities from Tiny

Type Vendor Product Version
ApplicationTinyMoxiemanager1.0
ApplicationTinyTinybrowser1.5.13
ApplicationTinyTinymce2.0.7