TinyMCE disclosed and patched several high-severity stored cross-site scripting vulnerabilities that let authenticated users with editing access inject malicious content later executed in other users’ browsers. The issues include CVE-2026-47759, which abuses unsanitized internal data-mce-* attributes to overwrite safe HTML during serialization; CVE-2026-47761, which exploits the media plugin through data-mce-object and related attributes; and CVE-2026-47762, which forges mce:protected comments to bypass sanitization in deployments using the protect option. The flaws can expose session tokens, cookies, and application data because the payloads run in the security context of the hosting application.
A separate high-severity bug, CVE-2026-47760, allows stored XSS through crafted nested SVG content because TinyMCE mishandles SVG namespace scope during sanitization. TinyMCE released fixes for the May disclosures in versions 5.11.1, 7.9.3, and 8.5.1, while the nested SVG issue was addressed in 7.1.0; however, the end-of-life 6.x branch remains unpatched for several of these vulnerabilities. GitHub security advisories and TinyMCE release documentation reflect the fixes, and no official workaround was provided for the affected branches and features.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On May 28, 2026, public reporting described CVE-2026-47759, CVE-2026-47761, and CVE-2026-47762 as stored XSS vulnerabilities in TinyMCE and attributed the findings to researcher Ivan Babenko (he1d3n). The disclosures noted that TinyMCE 6.x remained permanently affected because the branch is end-of-life.
TinyMCE addressed CVE-2026-47760, a stored XSS caused by improper SVG namespace scope tracking, in version 7.1.0. The issue was discovered by maple3142 of DEVCORE, and no workaround was available for affected users.
On May 20, 2026, the tinymce/tinymce GitHub Security Advisories page published multiple high-severity TinyMCE vulnerability disclosures, including issues involving nested SVGs, data-mce-* attributes, mce:protected comments, and media plugin data-mce-object injection. The listing also referenced earlier advisories from 2023 and 2024.
On May 20, 2026, TinyMCE released versions 5.11.1, 7.9.3, and 8.5.1 to fix CVE-2026-47759, CVE-2026-47761, and CVE-2026-47762. The end-of-life 6.x branch did not receive patches and remained affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcegithub.com
Open sourcetiny.cloud
Open sourcetiny.cloud
Open sourceapp.opencve.io
Open sourcetiny.cloud
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.