Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-47762

Опубликовано: 28 мая 2026
Источник: debian
EPSS Низкий

Описание

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tinymceremovedpackage

Примечания

  • https://github.com/tinymce/tinymce/security/advisories/GHSA-v98h-vmpc-fpqv

EPSS

Процентиль: 20%
0.00281
Низкий

Связанные уязвимости

CVSS3: 8.7
ubuntu
2 месяца назад

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

CVSS3: 8.7
nvd
2 месяца назад

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

CVSS3: 8.7
github
2 месяца назад

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

EPSS

Процентиль: 20%
0.00281
Низкий