Impact Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin en…
| CVE ID | CVE-2026-47761 |
| Vendor | npm |
| Affected Product | tinymce |
| Vulnerability Type | Vulnerability |
| CVSS Score | 8.7 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
#
Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled.
This vulnerability has been patched in TinyMCE 8.5.1, TinyMCE 7.9.3 and TinyMCE 5.11.1 LTS by ensuring that, when using the media plugin, any content with data-mce-object and data-mce-p-* attributes are properly sanitized.
No official workaround available.
To avoid this vulnerability: - Upgrade to TinyMCE 8.5.1 or higher.
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.