Cross-site scripting in TinyMCE - #VU131918
Published: May 20, 2026 / Updated: May 20, 2026
TinyMCE
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in data-mce-* attribute handling when parsing and serializing content containing data-mce-href, data-mce-src, or data-mce-style attributes. A remote user can inject malicious attribute values to execute arbitrary script code in a victim's browser.
User interaction is required to process crafted content.