TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinymce
Tinymce tinymce |
|
| Vendors & Products |
Tinymce
Tinymce tinymce |
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0. | |
| Title | TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T15:18:22.509Z
Reserved: 2026-05-19T22:36:16.881Z
Link: CVE-2026-47760
No data.
Status : Received
Published: 2026-05-28T16:16:28.210
Modified: 2026-05-28T16:16:28.210
Link: CVE-2026-47760
No data.
OpenCVE Enrichment
Updated: 2026-05-28T17:00:13Z
Weaknesses