TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
- Severity:
- High
Description
TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
- Affected version(s): >= 6.8.0, < 7.1.0
- Patched version(s): 7.1.0
References
Related Issues
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
- TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments - CVE-2026-47762
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761
- TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements - CVE-2024-38357
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on June 05, 2026


