• Advisory ID: DRUPAL-SA-CONTRIB-2010-025
  • Project: TinyMCE (third-party module)
  • Version: 5.x
  • Date: 2010-March-09
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting


The TinyMCE module provides a "WYSIWYG" tool for entering rich text into various parts of a site. The TinyMCE module displayed text entered by an admin without filtering that text leading to a Cross Site Scription (XSS) vulnerability. XSS vulnerabilities may expose site administrative accounts which could lead to a variety of additional compromises. This vulnerability is mitigated by the fact that an attacker must have the "administer tinymce" permission which should generally only be granted to trusted roles.

Versions affected

  • TinyMCE prior to 5.x-1.10.

Drupal core is not affected. If you do not use the contributed TinyMCE module for Drupal 5, there is nothing you need to do.


Install the latest version:

Reported by

Fixed by


The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.