Security News

Potentially Serious Vulnerability Found in Popular WYSIWYG Editor TinyMCE
2020-08-13 11:53

A potentially serious cross-site scripting vulnerability affecting the TinyMCE rich text editor can be exploited - depending on the implementation - for privilege escalation, obtaining information, or account takeover. Researchers at Bishop Fox discovered in April that TinyMCE is affected by an XSS vulnerability whose impact depends on the application using the editor.

Drupal 8 Updated to Patch Flaw in WYSIWYG Editor
2018-04-19 11:41

Updates released on Wednesday for Drupal 8 patch a moderately critical cross-site scripting (XSS) vulnerability affecting a third-party JavaScript library. The flaw impacts CKEditor, a WYSIWYG...