t
tinymce
Security Risk Profile
59
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 15, 2011 to present
10
Total CVEs
2
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
5.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
59/100
medium
Severity Distribution
Critical
0High
2Medium
8Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
5
2
CSRF
1
3
Input Validation
1
4
Code Injection
1
Most Affected Products
1. WordPress WordPress94
2. Moodle Moodle22
3. Phpletter Ajax File And Image Manager20
4. PhpMyFaq phpmyfaq20
5. TinyMCE Spellchecker Php11
Recent Vulnerabilities
See more →CVE-2026-47760
CVSS 8.7high
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
May 28, 2026
CVE-2025-1286
CVSS 6.1medium
Download HTML TinyMCE Button <= 1.2 - Reflected XSS
May 15, 2025🔧 No Patch
CVE-2025-24841
CVSS 5.4EPSS 0%medium
Feb 19, 2025🔧 No Patch
CVE-2014-3845
CVSS 6.8medium
May 22, 2014🔧 No Patch
CVE-2014-3844
CVSS 5.0medium
May 22, 2014🔧 No Patch
CVE-2012-4230
CVSS 4.3medium
Apr 25, 2014🔧 No Patch
CVE-2012-3414
CVSS 4.3medium
Jul 19, 2013🔧 No Patch
CVE-2013-2204
CVSS 4.3medium
Jul 8, 2013
CVE-2012-6112
CVSS 5.0medium
Jan 27, 2013
CVE-2011-4825
CVSS 7.5high
Dec 15, 2011🔧 No Patch
Monitor tinymce in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.