Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v98h-vmpc-fpqv

Опубликовано: 05 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

TinyMCE Cross-Site Scripting (XSS) vulnerability through mce:protected comments

Impact

Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option.

Patches

Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version.

Workarounds

No official workaround available.

Fix

To avoid this vulnerability:

Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial long-term support contract).

Acknowledgements

Tiny thanks Ivan Babenko for their help identifying this vulnerability.

Пакеты

Наименование

tinymce

npm
Затронутые версииВерсия исправления

<= 5.10.9

Отсутствует

Наименование

tinymce

npm
Затронутые версииВерсия исправления

>= 6.0.0, < 7.9.3

7.9.3

Наименование

tinymce

npm
Затронутые версииВерсия исправления

>= 8.0.0, < 8.5.1

8.5.1

Наименование

TinyMCE

nuget
Затронутые версииВерсия исправления

<= 5.10.9

Отсутствует

Наименование

TinyMCE

nuget
Затронутые версииВерсия исправления

>= 6.0.0, < 7.9.3

7.9.3

Наименование

TinyMCE

nuget
Затронутые версииВерсия исправления

>= 8.0.0, < 8.5.1

8.5.1

Наименование

tinymce/tinymce

composer
Затронутые версииВерсия исправления

<= 5.10.9

Отсутствует

Наименование

tinymce/tinymce

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 7.9.3

7.9.3

Наименование

tinymce/tinymce

composer
Затронутые версииВерсия исправления

>= 8.0.0, < 8.5.1

8.5.1

EPSS

Процентиль: 20%
0.00281
Низкий

8.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.7
ubuntu
2 месяца назад

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

CVSS3: 8.7
nvd
2 месяца назад

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

CVSS3: 8.7
debian
2 месяца назад

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, an ...

EPSS

Процентиль: 20%
0.00281
Низкий

8.7 High

CVSS3

Дефекты

CWE-79