{"id":"PYSEC-2026-1302","summary":"TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements","details":"### Impact\nA [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor.\n\n### Patches\nThis vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that content within noscript elements are properly parsed.\n\n### Fix\nTo avoid this vulnerability:\n\n* Upgrade to TinyMCE 7.2.0 or higher.\n* Upgrade to TinyMCE 6.8.4 or higher for TinyMCE 6.x.\n* Upgrade to TinyMCE 5.11.0 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract).\n\n### Acknowledgements\nTiny thanks [Malav Khatri](https://malavkhatri.com/) and another reporter for their help identifying this vulnerability.\n\n### References\n* [TinyMCE 6.8.4](https://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview)\n* [TinyMCE 7.2.0](https://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview)\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud)\n* Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues?q=is%3Aissue+is%3Aopen+sort%3Aupdated-desc)\n","aliases":["CVE-2024-38357","GHSA-w9jx-4g6g-rp7x"],"modified":"2026-07-07T17:46:38.052584330Z","published":"2026-07-07T14:34:34.892620Z","references":[{"type":"WEB","url":"https://github.com/tinymce/tinymce/security/advisories/GHSA-w9jx-4g6g-rp7x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38357"},{"type":"WEB","url":"https://github.com/tinymce/tinymce/commit/5acb741665a98e83d62b91713c800abbff43b00d"},{"type":"WEB","url":"https://github.com/tinymce/tinymce/commit/a9fb858509f86dacfa8b01cfd34653b408983ac0"},{"type":"PACKAGE","url":"https://github.com/tinymce/tinymce"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/xss"},{"type":"WEB","url":"https://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview"},{"type":"WEB","url":"https://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview"},{"type":"PACKAGE","url":"https://pypi.org/project/django-tinymce"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w9jx-4g6g-rp7x"}],"affected":[{"package":{"name":"django-tinymce","ecosystem":"PyPI","purl":"pkg:pypi/django-tinymce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.0"}]}],"versions":["1.0","1.1","1.2","1.3","1.4","1.4.1","1.5","1.5.1","1.5.1.dev100","1.5.1.dev101","1.5.1a1","1.5.1a2","1.5.1a3","1.5.1b1","1.5.1b2","1.5.1b3","1.5.1b4","1.5.2","1.5.3","1.5.4","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.1.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.7.0","2.7.1","2.8.0","2.9.0","3.0.1","3.0.2","3.1.0","3.2.0","3.3.0","3.4.0","3.5.0","3.6.0","3.6.1","3.7.0","3.7.1","4.0.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django-tinymce/PYSEC-2026-1302.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:L"}]}