Skip to content

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

High severity GitHub Reviewed Published May 20, 2026 in tinymce/tinymce • Updated Jun 5, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts