CVE-2026-47759

HIGH

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

Title source: cna
STIX 2.1

Description

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

References (3)

Core 3

Scores

CVSS v3 8.7
EPSS 0.0021
EPSS Percentile 11.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (14)
npm/tinymce 0npm
npm/tinymce 6.0.0 - 7.9.3npm
npm/tinymce 8.0.0 - 8.5.1npm
nuget/TinyMCE 0 - 5.11.1NuGet
nuget/TinyMCE 6.0.0 - 7.9.3NuGet
nuget/TinyMCE 8.0.0 - 8.5.1NuGet
tiny/tinymce < 5.11.1
tinymce/tinymce 0Packagist
tinymce/tinymce 6.0.0 - 7.9.3Packagist
tinymce/tinymce 8.0.0 - 8.5.1Packagist
... and 4 more
Published May 28, 2026
Tracked Since May 28, 2026