CVE-2026-47760

Updated on 28 May 2026

Severity

8.7 High severity

Details

CVSS score
8.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Overview

About vulnerability

Impact

TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript.

Patches

This issue affects TinyMCE 6.8.x-7.0.x. The vulnerability is fixed in TinyMCE 7.1.0 and later.

Workarounds

No official workaround available.

Acknowledgements

Tiny thanks maple3142 (https://maple3142.net) of DEVCORE for their help identifying this vulnerability.

References

Fix introduced in TinyMCE 7.1.0 though a rewrite of code causing the vulnerability.

Details

Affected product:
tinymce
Affected packages:
tinymce @ 6.8.6

Fixes