TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
- Severity:
- High
Description
Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **> 0, <= 5.10.9 >= 8.0.0, < 8.5.1 >= 6.0.0, < 7.9.3** Patched version(s): **8.5.1 7.9.3**
References
Related Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
- TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments - CVE-2026-47762
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on June 30, 2026


