Description
A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE’s unfiltered notification system, which is used in error handling.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
Affected version(s): **< 5.10.8 >= 6.0.0, < 6.7.1** Patched version(s): **5.10.8 6.7.1**
References
Could your website be exposed too?
SmartScanner can check your website for TinyMCE XSS vulnerability in notificationManager.open API and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin - CVE-2023-45818
- XSS Attack with Express API - CVE-2023-23630
- NASA Open MCT Cross Site Scripting vulnerability - CVE-2023-45885
- TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments - CVE-2026-47762


