← العودة للجدول
CVE-2026-47760
CVE-2026-47760 — GHSA: TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
📅 2026-06-05
🟠 High 🔥 No GHSA Exploit Web CVSS 8.7 🎯 EPSS 0.03%

📋 الوصف الكامل

### Impact TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. ### Patches This issue affects TinyMCE 6.8.x-7.0.x. The vulnerability is fixed in TinyMCE 7.1.0 and later. ### Workarounds No official workaround available. ### Acknow

💻 الأنظمة المتأثرة

GHSA: TinyMCE Cross-Site

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-47760

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←