Stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation.
Patched by stripping unsafe data-mce-* attributes during parsing. Users should upgrade to the latest patched versions (5 LTS, 7.x, 8.x).
No official workaround available.
To avoid this vulnerability:
Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial long-term support contract).
Tiny thanks Tadi Kadango (website) and Ivan Babenko for their help identifying this vulnerability.
{
"github_reviewed": true,
"github_reviewed_at": "2026-06-05T20:27:50Z",
"nvd_published_at": "2026-05-28T16:16:28Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-79"
]
}