Vulnerabilities/

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

Severity:
High

Description

Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled.

Recommendation

Update the tinymce package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinymce
Anything's wrong? Let us know Last updated on June 30, 2026