TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
References
| Link | Resource |
|---|---|
| https://github.com/tinymce/tinymce/security/advisories/GHSA-v98h-vmpc-fpqv | Vendor Advisory |
| https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/#overview | Release Notes |
| https://www.tiny.cloud/docs/tinymce/8/8.5.1-release-notes/#overview | Release Notes |
Configurations
Configuration 1 (hide)
|
History
28 May 2026, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:* | |
| First Time |
Tiny
Tiny tinymce |
|
| References | () https://github.com/tinymce/tinymce/security/advisories/GHSA-v98h-vmpc-fpqv - Vendor Advisory | |
| References | () https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/#overview - Release Notes | |
| References | () https://www.tiny.cloud/docs/tinymce/8/8.5.1-release-notes/#overview - Release Notes |
28 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 16:16
Updated : 2026-05-28 19:18
NVD link : CVE-2026-47762
Mitre link : CVE-2026-47762
CVE.ORG link : CVE-2026-47762
JSON object : View
Products Affected
tiny
- tinymce
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
