CVE-2026-47761
EUVD-2026-3292228.05.2026, 16:16
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tiny | tinymce | 𝑥 < 5.11.1 |
| tiny | tinymce | 6.0.0 ≤ 𝑥 < 7.9.3 |
| tiny | tinymce | 8.0.0 ≤ 𝑥 < 8.5.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tinymce | tinymce | 𝑥 < 5.11.1 | CNA |