Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh5m-5hw4-5c69

Опубликовано: 05 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

Impact

TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript.

Patches

This issue affects TinyMCE 6.8.x-7.0.x. The vulnerability is fixed in TinyMCE 7.1.0 and later.

Workarounds

No official workaround available.

Acknowledgements

Tiny thanks maple3142 (https://maple3142.net) of DEVCORE for their help identifying this vulnerability.

References

Fix introduced in TinyMCE 7.1.0 though a rewrite of code causing the vulnerability.

Пакеты

Наименование

tinymce

npm
Затронутые версииВерсия исправления

>= 6.8.0, < 7.1.0

7.1.0

Наименование

TinyMCE

nuget
Затронутые версииВерсия исправления

>= 6.8.0, < 7.1.0

7.1.0

Наименование

tinymce/tinymce

composer
Затронутые версииВерсия исправления

>= 6.8.0, < 7.1.0

7.1.0

EPSS

Процентиль: 9%
0.00191
Низкий

8.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.7
ubuntu
2 месяца назад

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

CVSS3: 8.7
nvd
2 месяца назад

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

CVSS3: 8.7
debian
2 месяца назад

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0 ...

EPSS

Процентиль: 9%
0.00191
Низкий

8.7 High

CVSS3

Дефекты

CWE-79