CVE-2026-47761: TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-47761 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →