TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
GHSA-q742-qvgc-gc2f · CVE-2026-47759
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation.
Patches
Patched by stripping unsafe data-mce-* attributes during parsing. Users should upgrade to the latest patched versions (5 LTS, 7.x, 8.x).
Workarounds
No official workaround available.
Fix
To avoid this vulnerability:
Upgrade to TinyMCE 8.5.1 or higher.
Upgrade to TinyMCE 7.9.3 or higher.
Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial long-term support contract).
Acknowledgements
Tiny thanks Tadi Kadango (website) and Ivan Babenko for their help identifying this vulnerability.
References
- WEB https://github.com/tinymce/tinymce/security/advisories/GHSA-q742-qvgc-gc2f
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-47759
- PACKAGE https://github.com/tinymce/tinymce
- WEB https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/#overview
- WEB https://www.tiny.cloud/docs/tinymce/8/8.5.1-release-notes/#overview
Ready to move
Start Securing
Free, no credit card | First findings in minutes