Vulnerabilities/

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

Severity:
High

Description

TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript.

Recommendation

Update the tinymce package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tinymce
Anything's wrong? Let us know Last updated on June 05, 2026