CVE-2026-47759
EUVD-2026-3292128.05.2026, 16:16
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tiny | tinymce | 𝑥 < 5.11.1 |
| tiny | tinymce | 6.0.0 ≤ 𝑥 < 7.9.3 |
| tiny | tinymce | 8.0.0 ≤ 𝑥 < 8.5.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tinymce | tinymce | 𝑥 < 5.11.1 | CNA |