logo

Critical TinyMCE Cross Site Scripting Flaws Threaten Millions of Applications

ID: 36cca833-9342-5d81-87a0-970b4f97fd27

STIX ID: report--36cca833-9342-5d81-87a0-970b4f97fd27

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

A security advisory details multiple critical cross-site scripting and sanitization vulnerabilities in the TinyMCE rich text editor that allow remote attackers to inject and execute malicious scripts via crafted media plugin attributes, improper namespace handling in the sanitizer, prefixed source/link attributes, and forged document comments; the flaws affect widely deployed versions and require immediate patching (upgrade to 7.9.3+, 8.5.1 or obtain LTS fixes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.