216.73.216.31

CVE-2026-47761

· Published 28/05/2026 16:16 · Modified 28/05/2026 19:18

Labels: CVE-2026-47761 2026-05-28CVE-2026-47761CWE-79[email protected]

Essential information

Published
28/05/2026 16:16
Modified
28/05/2026 19:18
Author
Creator
CVSS
8.7 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CVSS metrics

Description

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tiny / tinymce cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*
tiny / tinymce cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*
tiny / tinymce cpe:2.3:a:tiny:tinymce:*:*:*:*:*:*:*:*

References