Vulnerabilities/

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

Severity:
High

Description

Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option.

Recommendation

Update the tinymce package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinymce
Anything's wrong? Let us know Last updated on July 15, 2026