Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.22% | — | Kvvaradha KV Tinymce Editor ADD Fonts | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions. | |
| Modificada | Media (4.8) | 0.54% | — | Tinymce Custom Styles Project Tinymce Custom Styles | 10/7/2023 | 17/6/2026 | The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.39% | — | Tinymce Custom Styles Project Tinymce Custom Styles | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tim Reeves & David Stöckl TinyMCE Custom Styles plugin <= 1.1.2 versions. | |
| Modificada | Media (6.1) | 0.98% | — | Tinymce | 8/12/2022 | 17/6/2026 | tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the `image` plugin, which presents these… | |
| Modificada | Media (6.1) | 0.80% | — | Custom Tinymce Shortcode Button Project Custom Tinymce Shortcode Button | 16/5/2022 | 17/6/2026 | The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 1.8% | — | Tinymce | 14/8/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode. | |
| Modificada | Media (6.1) | 1.2% | — | Tinymce | 10/8/2020 | 17/6/2026 | TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor. | |
| Modificada | Media (6.1) | 1.9% | — | Tinymce | 17/7/2019 | 17/6/2026 | tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab. | |
| Modificada | Media (6.8) | 0.95% | — | Tinymce Color Picker | 22/5/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that change plugin settings via unknown vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.8% | — | Tinymce Color Picker | 22/5/2014 | 17/6/2026 | The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.4% | — | Tinymce | 25/4/2014 | 16/6/2026 | The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element. | |
| Modificada | Media (4.3) | 9.1% | — | Swfupload Project SwfuploadTinymce Image ManagerWordpress | 19/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function. | |
| Modificada | Media (4.3) | 2.9% | — | Tinymce MediaWordpress | 8/7/2013 | 16/6/2026 | moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extraction of the QUERY_STRING, which allows remote attackers to pass arbitrary parameters to a Flash application, and conduct… | |
| Modificada | Media (5) | 2.3% | — | Tinymce Spellchecker PHPMoodle | 27/1/2013 | 16/6/2026 | classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger… | |
| Modificada | Alta (7.5) | 39% | — | Phpletter Ajax File AND Image ManagerPhpmyfaqTinymce | 15/12/2011 | 16/6/2026 | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters. | |
| Rechazada | Sin puntuar | — | — | TinymceAI | 4/2/2009 | 7/11/2023 | Rejected reason: SQL injection vulnerability in index.php in TinyMCE 2.0.1 allows remote attackers to execute arbitrary SQL commands via the menuID parameter. NOTE: CVE and multiple reliable third parties dispute this issue, since TinyMCE does not contain index.php or any PHP code. This may be an issue in a product… | |
| Modificada | Media (6.4) | 6.0% | — | Moxiecode Tinymce Compressor PHP | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Moxiecode Tinymce Compressor PHP | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter. |