Description
TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
- Affected version(s): >= 6.8.0, < 7.1.0
- Patched version(s): 7.1.0
References
Could your website be exposed too?
SmartScanner can check your website for TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments - CVE-2026-47762
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements - CVE-2024-38357
You might also like:
See something that needs correcting? Let us knowUpdated June 05, 2026


