← العودة للجدول
CVE-2026-47762
CVE-2026-47762 — GHSA: TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
📅 2026-06-05
🟠 High 🔥 No GHSA Exploit Web CVSS 8.7 🎯 EPSS 0.03%

📋 الوصف الكامل

### Impact Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. ### Patches Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version. ### Workar

💻 الأنظمة المتأثرة

GHSA: TinyMCE Cross-Site

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-47762

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←