PT-2026-44388 · Tiny+1 · Tinymce

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-47759

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-47759

Affected Products

Tinymce