37 exploited vulnerabilities in Tinymce
- Vendors
- Orchard, Tinymce, Joplin, Node.Js, Joomla, Thorsten Rinne
- With known exploits
- 37
- Affected Orchardproject Orchard versions
- < 1.10
- Affected Tiny Tinymce versions
- < 5.11.1, 7.9.3, 8.5.1, 5.10.9, 6.7.3, 5.10.8, 6.7.1
- Affected Tiny Tinybrowser versions
- < 1.5.13
- Affected Phpletter Ajax File And Image Manager versions
- β€ 1.0, 0.5, 0.5.5, 0.5.7, 0.6, 0.6.12, 0.7.8, 0.7.10, 0.8, 0.8.8, 0.8.9, 0.8.24, 0.9
- Affected Phpmyfaq versions
- = 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9, 2.6.10, 2.6.11, 2.6.12, 2.6.13, 2.6.14, 2.6.15, 2.6.16, 2.6.17, 2.6.18, 2.7.0
- Affected Tinymce versions
- β€ 1.4.1, 3.5.8
- Affected Cmsmadesimple Cms Made Simple versions
- β€ 1.2.2
- Affected Isic.lk Project Isic.lk versions
- β€ 2018-02-13
Vulnerabilities with exploits
Highest CVSS first β 11 of these already have exploit code on Sploitus
CVE-2020-29592
CVE-2026-47762
CVE-2026-47761
CVE-2026-47760
CVE-2026-47759
CVE-2023-38506
CVE-2011-4906 1 exploit
CVE-2011-4825 11 exploits
CVE-2007-6656 1 exploit
CVE-2022-30529
CVE-2025-62418
CVE-2010-5281 1 exploit
CVE-2023-30943 3 exploits
Exploit for External Control of File Name or Path in MoodleExploit for External Control of File Name or Path in Moodle
CVE-2012-1467 2 exploits
Open Journal Systems 2.3.6 XSS / File Manipulation / Shell UploadOpen Journal Systems (OJS) 2.3.6 - 'rfiles.php' Traversal Arbitrary File Manipulation
CVE-2024-38357
CVE-2024-38356
CVE-2024-29881
CVE-2024-29203
CVE-2023-48219
CVE-2023-45819
CVE-2023-45818
CVE-2024-21911
CVE-2024-21910
CVE-2024-21908
CVE-2020-17480
CVE-2019-1010091
CVE-2022-23494
CVE-2020-5809
CVE-2013-4791
CVE-2011-5147 1 exploit
CVE-2011-3718
CVE-2008-7212
CVE-2021-35955
CVE-2013-3630 9 exploits
Moodle Authenticated Spelling Binary Remote Code Execution ExploitMoodle SpellChecker Path Authenticated Remote Command Execution Exploit
CVE-2012-4230 1 exploit
CVE-2012-1469 3 exploits
Open Journal Systems 2.3.6 XSS / File Manipulation / Shell UploadOpen Journal Systems (OJS) 2.3.6 - 'index.php?authors[][url]' Cross-Site Scripting
CVE-2009-2043 1 exploit