{"id":"GHSA-27gm-ghr9-4v95","summary":"Cross-site scripting vulnerability in TinyMCE","details":"### Impact\nA cross-site scripting (XSS) vulnerability was discovered in: the core parser, `paste` and `visualchars` plugins. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor via the clipboard or APIs. This impacts all users who are using TinyMCE 4.9.6 or lower and TinyMCE 5.1.3 or lower.\n\n### Patches\nThis vulnerability has been patched in TinyMCE 4.9.7 and 5.1.4 by improved parser logic and HTML sanitization.\n\n### Workarounds\nThe workarounds available are:\n- disable the impacted plugins\n- manually sanitize the content using the `BeforeSetContent` event (see below)\n- upgrade to either TinyMCE 4.9.7 or TinyMCE 5.1.4\n\n#### Example: Manually sanitize content\n```js\neditor.on('BeforeSetContent', function(e) {\n  var sanitizedContent = ...; // Manually sanitize content here\n  e.content = sanitizedContent;\n});\n```\n\n### Acknowledgements\nTiny Technologies would like to thank Michał Bentkowski for discovering this vulnerability.\n\n### References\nhttps://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues)\n* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)\n","aliases":["CVE-2020-17480"],"modified":"2026-07-08T06:00:37.470385260Z","published":"2020-01-30T21:22:15Z","database_specific":{"github_reviewed_at":"2020-01-30T19:38:09Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-17480"},{"type":"PACKAGE","url":"https://github.com/tinymce/tinymce"},{"type":"WEB","url":"https://portswigger.net/daily-swig/xss-vulnerability-patched-in-tinymce"},{"type":"WEB","url":"https://www.tiny.cloud/docs/release-notes/release-notes514/#securityfixes"}],"affected":[{"package":{"name":"tinymce","ecosystem":"npm","purl":"pkg:npm/tinymce"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.9.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-27gm-ghr9-4v95/GHSA-27gm-ghr9-4v95.json"}},{"package":{"name":"tinymce","ecosystem":"npm","purl":"pkg:npm/tinymce"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-27gm-ghr9-4v95/GHSA-27gm-ghr9-4v95.json"}}],"schema_version":"1.9.0"}