CVE-2026-47762 is a stored cross-site scripting vulnerability in TinyMCE affecting versions prior to 5.11.1, 7.9.3, and 8.5.1. The flaw is in the content protection mechanism used by the protect configuration option, which preserves matched content by converting it into serialized protected comment placeholders and later restoring it back into raw HTML. TinyMCE fails to validate that restored mce:protected comment content is authentic and matches the configured protection rules before decoding and reinserting it. An attacker with editing privileges can forge protected comments containing malicious markup or script-bearing payloads that bypass the normal sanitization pipeline and are restored into the DOM when the content is viewed or edited. This results in persistent script execution in the browsers of users who load the affected content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
protect option where feasible, restricting editor access to trusted users only, applying strict server-side HTML sanitization and validation before storing or rendering content, and enforcing a strong Content Security Policy as defense in depth. Additional browser-side hardening such as HTTPS with HSTS may further reduce secondary risk but does not remediate the underlying flaw.Patch, then assume compromise.
protect regular-expression rules before being restored. TinyMCE 6.x is end-of-life and does not receive a patch; affected 6.x deployments should migrate to a supported fixed branch.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TinyMCE document comment handler vulnerability where forged comments bypass sanitization during restoration of hidden data blocks, enabling script injection.
A stored cross-site scripting vulnerability in TinyMCE's handling of protected custom markup preservation patterns, allowing forged internal comment placeholders to be restored as executable markup and bypass sanitization.
A stored XSS vulnerability in TinyMCE via forged mce:protected comments that can bypass sanitization and execute injected scripts when content is restored.
A stored cross-site scripting vulnerability in TinyMCE's protect/content restoration mechanism that allows forged mce:protected comments to bypass sanitization and restore attacker-controlled JavaScript into the DOM.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.