CVE-2026-47760: TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

Published May 28, 2026
·
Updated

Impact TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested <svg> elements can bypass attribute sanitization and execute arbitrary JavaScript.

Patches This issue affects TinyMCE 6.8.x-7.0.x. The vulnerability is fixed in TinyMCE 7.1.0 and later.

Workarounds No official workaround available.

Acknowledgements Tiny thanks maple3142 (<https://maple3142.net>) of DEVCORE for their help identifying this vulnerability.

References Fix introduced in TinyMCE 7.1.0 though a rewrite of code causing the vulnerability.

Other sources

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

NVD

Affected Software

5 affected componentsFixes available
TinyMCE TinyMCE>=6.8.0<7.1.0
Tiny TinyMCE>=6.8.0<7.1.0
composer/tinymce/tinymce>=6.8.0<7.1.0
7.1.0
nuget/TinyMCE>=6.8.0<7.1.0
7.1.0
npm/tinymce>=6.8.0<7.1.0
7.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/tinymce/tinymce to a version that resolves this vulnerability.

    Fixed in 7.1.0
  2. Upgrade

    Upgrade nuget/TinyMCE to a version that resolves this vulnerability.

    Fixed in 7.1.0
  3. Upgrade

    Upgrade npm/tinymce to a version that resolves this vulnerability.

    Fixed in 7.1.0

Event History

May 28, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 5, 2026
Advisory Published
via GitHub·08:09 PM
Data Sourced
via GitHub·08:09 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-47760?

CVE-2026-47760 has a high severity rating of 8.7.

2

How do I fix CVE-2026-47760?

To fix CVE-2026-47760, upgrade TinyMCE to version 7.1.0 or later.

3

What type of vulnerability is CVE-2026-47760?

CVE-2026-47760 is a Cross-Site Scripting (XSS) vulnerability.

4

What causes the vulnerability in CVE-2026-47760?

The vulnerability in CVE-2026-47760 is caused by improper handling of SVG namespace scope in the TinyMCE sanitizer.

5

What can attackers achieve with CVE-2026-47760?

Attackers can bypass attribute sanitization and execute arbitrary JavaScript using crafted payloads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203