Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-47760

Опубликовано: 28 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.7

Описание

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 9%
0.00191
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
2 месяца назад

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

CVSS3: 8.7
debian
2 месяца назад

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0 ...

CVSS3: 8.7
github
2 месяца назад

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

EPSS

Процентиль: 9%
0.00191
Низкий

8.7 High

CVSS3