Junglewise Threat Intelligence

CVE-2026-47759: TinyMCE stored XSS via unsanitized data-mce attributes

CVE-2026-47759 · Severity: high · CVSS 8.7 · Published 2026-05-28

Technologies: Tinymce.

Executive brief

TinyMCE, a widely used rich-text editor for web applications, is vulnerable to a security flaw that allows attackers to inject malicious scripts into content. If an attacker saves a specially crafted document, other users viewing that content could have their accounts compromised or sensitive data stolen. This occurs because the editor fails to properly clean certain internal attributes used for styling and links.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in TinyMCE due to improper neutralization of 'data-mce-' prefixed attributes, specifically data-mce-href, data-mce-src, and data-mce-style. During the serialization process, these unsanitized internal attributes can override their safe counterparts (src, href, style), allowing an attacker with low privileges to bypass standard validation filters. An attacker can exploit this by submitting malicious content that, when rendered by another user, executes arbitrary JavaScript in the victim's browser. The vulnerability is patched in versions 5.11.1 LTS, 7.9.3, and 8.5.1 by stripping these unsafe attributes during parsing.

Affected products

  • TinyMCE tinymce < 5.11.1, >= 6.0.0 < 7.9.3, >= 8.0.0 < 8.5.1

Timeline

  • 2026-05-20: disclosed: Initial disclosure to tinymce/tinymce repository
  • 2026-05-28: advisory: NVD publication date
  • 2026-06-05: advisory: GitHub Advisory Database publication date

References