[wp-trac] [WordPress Trac] #49736: The tinymce package is vulnerable to Cross-Site Scripting (XSS) attacks.

WordPress Trac noreply at wordpress.org
Wed Apr 1 00:22:38 UTC 2020


#49736: The tinymce package is vulnerable to Cross-Site Scripting (XSS) attacks.
--------------------------------+----------------------
 Reporter:  tlterry             |       Owner:  (none)
     Type:  defect (bug)        |      Status:  closed
 Priority:  normal              |   Milestone:
Component:  External Libraries  |     Version:
 Severity:  critical            |  Resolution:  invalid
 Keywords:                      |     Focuses:
--------------------------------+----------------------
Changes (by azaozz):

 * status:  new => closed
 * resolution:   => invalid
 * milestone:  Awaiting Review =>


Comment:

 @tlterry please see
 https://core.trac.wordpress.org/ticket/49735#comment:1. It's not a good
 idea to open such tickets on trac.

 This report also seems to be invalid. WordPress doesn't include the
 `preview` TinyMCE plugin.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/49736#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list