Cross-site scripting in tinymce - #VU131917
Published: May 20, 2026
tinymce
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript.
The vulnerability exists due to improper SVG namespace scope handling in the sanitizer when parsing crafted content with nested SVG elements. A remote user can supply a specially crafted payload to execute arbitrary JavaScript.
User interaction is required to process the crafted content.