Aller au contenu

Fiche vulnérabilité

CVE-2026-47760 : faille moyenne tiny tinymce (CVSS 5.4)

Description

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
28 mai 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • tiny tinymce

Références

Rechercher une autre vulnérabilité dans la base CVE