PT-2026-44390 · Tiny+1 · Tinymce

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-47761

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-47761

Affected Products

Tinymce