Description
Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **<= 5.10.9 >= 8.0.0, < 8.5.1 >= 6.0.0, < 7.9.3** Patched version(s): **8.5.1 7.9.3**
References
Could your website be exposed too?
SmartScanner can check your website for TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881


