Description
A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation layer, it is manipulated as a string by internal trimming functions before being stored in the undo stack.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **< 5.10.8 >= 6.0.0, < 6.7.1** Patched version(s): **5.10.8 6.7.1**
References
Could your website be exposed too?
SmartScanner can check your website for TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinyMCE XSS vulnerability in notificationManager.open API - CVE-2023-45819
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761
- Unauthorized Access to Private Fields in User Registration API - @strapi/plugin-users-permissions - CVE-2023-39345
- Strapi Improper Rate Limiting vulnerability - @strapi/plugin-users-permissions - CVE-2023-38507


