CVE-2026-47759: Tiny Tinymce

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

Affected products

  • Tiny Tinymce: before 5.11.1 (fixed in 5.11.1); from 6.0.0, before 7.9.3 (fixed in 7.9.3); from 8.0.0, before 8.5.1 (fixed in 8.5.1)

Published 2026-05-28. Last modified 2026-06-17.