TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
- Severity:
- High
Description
Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **<= 5.10.9 >= 8.0.0, < 8.5.1 >= 6.0.0, < 7.9.3** Patched version(s): **8.5.1 7.9.3**
References
Related Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on July 15, 2026


