CVE-2026-47761: Tiny Tinymce
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.
Affected products
- Tiny Tinymce: before 5.11.1 (fixed in 5.11.1); from 6.0.0, before 7.9.3 (fixed in 7.9.3); from 8.0.0, before 8.5.1 (fixed in 8.5.1)
Published 2026-05-28. Last modified 2026-06-17.