


Perceptive Security
SOC/SIEM Consultancy

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-m…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 17:06:19
Source:
nvd.nist.gov
Web Technologies
TinyMCE open source rich text editor contains a stored XSS vulnerability in versions prior to 5.11.1, 7.9.3, and 8.5.1. The vulnerability exists in unsanitized data-mce-* attributes including data-mce-href, data-mce-src, and data-mce-style. Attackers can inject malicious values that override safe attributes during serialization, effectively bypassing validation mechanisms. This allows for stored cross-site scripting attacks that persist in the application. The vulnerability has been patched in the specified versions across all affected release branches.
Technical details
Mitigation steps:
Affected products:
TinyMCE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47759
https://github.com/tinymce/tinymce/security/advisories/GHSA-q742-qvgc-gc2f
https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/#overview
https://www.tiny.cloud/docs/tinymce/8/8.5.1-release-notes/#overview
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
