What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and Styles: from n/a through 1.1.2.
Explanation of Vulnerability in Simple Terms
02Summary
A cross-site request forgery (CSRF) vulnerability in TinyMCE Advanced Professional Formats and Styles allows an attacker to perform unwanted actions on behalf of a logged-in user. The vulnerability requires the user to visit a malicious webpage while authenticated. An attacker can modify site content or settings through forged requests, but cannot read sensitive data.
What an attacker can do
03Attacker Capabilities
Perform unwanted actions (like modifying content) on behalf of a logged-in site user.
Potential impact on your site
04Site Impact
Site content or editor settings could be altered without the user's knowledge if they visit a malicious link while logged in.
Conditions required to exploit
05Prerequisites
User must be logged in and visit an attacker-controlled webpage while authenticated.
Key dates
06Disclosure timeline
February 21, 2024
CVE published
April 28, 2026
Record updated