Cross-site scripting in TinyMCE - #VU131919
Published: May 20, 2026 / Updated: May 20, 2026
TinyMCE
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in mce:protected comment handling when restoring protected content. A remote user can forge mce:protected comments to bypass sanitization and inject script that executes when content is restored to execute arbitrary script in a victim's browser.
Only users who utilize the protect option are affected, and user interaction is required.