📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Technology and Software Development HIGH 1h Global vulnerability Government and Federal Agencies CRITICAL 1h Global supply_chain Software Development and Open-Source Ecosystems HIGH 2h Global vulnerability Enterprise Software/SaaS MEDIUM 2h Global supply_chain Software Development HIGH 3h Global general Insurance/Risk Management HIGH 3h Global data_breach Enterprise Software / Information Technology CRITICAL 4h Global vulnerability Technology/Software CRITICAL 6h Global malware Social Media and Consumer Technology HIGH 6h Global botnet Information Technology and IoT HIGH 6h Global vulnerability Technology and Software Development HIGH 1h Global vulnerability Government and Federal Agencies CRITICAL 1h Global supply_chain Software Development and Open-Source Ecosystems HIGH 2h Global vulnerability Enterprise Software/SaaS MEDIUM 2h Global supply_chain Software Development HIGH 3h Global general Insurance/Risk Management HIGH 3h Global data_breach Enterprise Software / Information Technology CRITICAL 4h Global vulnerability Technology/Software CRITICAL 6h Global malware Social Media and Consumer Technology HIGH 6h Global botnet Information Technology and IoT HIGH 6h Global vulnerability Technology and Software Development HIGH 1h Global vulnerability Government and Federal Agencies CRITICAL 1h Global supply_chain Software Development and Open-Source Ecosystems HIGH 2h Global vulnerability Enterprise Software/SaaS MEDIUM 2h Global supply_chain Software Development HIGH 3h Global general Insurance/Risk Management HIGH 3h Global data_breach Enterprise Software / Information Technology CRITICAL 4h Global vulnerability Technology/Software CRITICAL 6h Global malware Social Media and Consumer Technology HIGH 6h Global botnet Information Technology and IoT HIGH 6h
Vulnerabilities

CVE-2026-47761

High
CWE-79 — Weakness Type
Published: May 28, 2026  ·  Modified: May 31, 2026  ·  Source: NVD
CVSS v3
8.7
🔗 NVD Official
📄 Description (English)

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

🤖 AI Executive Summary

TinyMCE versions prior to 5.11.1, 7.9.3, and 8.5.1 contain a stored XSS vulnerability in the media plugin allowing attackers to inject malicious scripts via crafted data-mce-* attributes. The vulnerability executes when content is rendered, affecting all organizations using TinyMCE with the media plugin enabled. With a CVSS score of 8.7, this poses significant risk to content management systems, web applications, and digital platforms widely deployed across Saudi organizations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 30, 2026 08:24
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses critical risk to Saudi banking sector (SAMA-regulated institutions using TinyMCE in customer portals), government agencies (NCA oversight), healthcare providers (SEHA systems), telecommunications operators (STC, Mobily), and e-commerce platforms. Media plugin usage in content management systems across these sectors creates widespread exposure. Stored XSS enables account takeover, credential theft, malware distribution, and unauthorized access to sensitive customer/citizen data. Saudi organizations managing Arabic content are particularly vulnerable as attackers can inject scripts targeting RTL text processing.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare and Medical Services Energy and Utilities Telecommunications E-commerce and Retail Education Media and Publishing
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all TinyMCE installations: Scan internal systems, web applications, and CMS platforms for TinyMCE versions < 5.11.1, < 7.9.3, and < 8.5.1
2. Disable media plugin: If immediate patching is not possible, disable the media plugin in TinyMCE configuration
3. Audit stored content: Review database for suspicious data-mce-* attributes in media elements

PATCHING GUIDANCE:
1. Upgrade to patched versions: Update to TinyMCE 5.11.1, 7.9.3, or 8.5.1 immediately
2. Test in staging: Validate functionality with Arabic content and RTL text before production deployment
3. Implement change management: Document all version updates and test media plugin functionality

COMPENSATING CONTROLS (if patching delayed):
1. Input validation: Implement strict whitelist validation for data-mce-* attributes
2. Content Security Policy: Deploy CSP headers to restrict inline script execution
3. Output encoding: Ensure all user-generated content is properly HTML-encoded before rendering
4. WAF rules: Configure Web Application Firewall to block requests containing suspicious data-mce-* patterns

DETECTION RULES:
1. Monitor for data-mce-* attributes in POST/PUT requests to content endpoints
2. Alert on script tags or event handlers within media element attributes
3. Log all TinyMCE configuration changes and plugin modifications
4. Track database modifications to content tables containing media elements
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع تثبيتات TinyMCE: مسح الأنظمة الداخلية وتطبيقات الويب ومنصات إدارة المحتوى للبحث عن إصدارات TinyMCE < 5.11.1 و < 7.9.3 و < 8.5.1
2. تعطيل مكون الوسائط: إذا لم يكن من الممكن تطبيق التصحيح فوراً، قم بتعطيل مكون الوسائط في إعدادات TinyMCE
3. تدقيق المحتوى المخزن: مراجعة قاعدة البيانات للبحث عن سمات data-mce-* المريبة في عناصر الوسائط

إرشادات التصحيح:
1. الترقية إلى الإصدارات المصححة: تحديث إلى TinyMCE 5.11.1 أو 7.9.3 أو 8.5.1 فوراً
2. الاختبار في بيئة التطوير: التحقق من الوظائف مع المحتوى العربي والنصوص من اليمين إلى اليسار قبل النشر في الإنتاج
3. تطبيق إدارة التغيير: توثيق جميع تحديثات الإصدارات واختبار وظائف مكون الوسائط

الضوابط البديلة (إذا تأخر التصحيح):
1. التحقق من المدخلات: تطبيق التحقق من القائمة البيضاء الصارمة لسمات data-mce-*
2. سياسة أمان المحتوى: نشر رؤوس CSP لتقييد تنفيذ النصوص البرمجية المضمنة
3. ترميز المخرجات: التأكد من ترميز جميع المحتوى الذي ينشئه المستخدمون بشكل صحيح قبل العرض
4. قواعد جدار الحماية: تكوين جدار الحماية لحجب الطلبات التي تحتوي على أنماط data-mce-* المريبة

قواعد الكشف:
1. مراقبة سمات data-mce-* في طلبات POST/PUT إلى نقاط نهاية المحتوى
2. التنبيه على علامات النصوص البرمجية أو معالجات الأحداث ضمن سمات عناصر الوسائط
3. تسجيل جميع تغييرات إعدادات TinyMCE وتعديلات المكونات
4. تتبع تعديلات قاعدة البيانات على جداول المحتوى التي تحتوي على عناصر وسائط
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.14.2.5 - Addressing information security in supplier agreements ECC 2024 A.5.23 - Web application security controls
🔵 SAMA CSF
SAMA CSF 1.1 - Governance and Risk Management SAMA CSF 2.2 - Information and Communications Technology Security SAMA CSF 2.2.1 - System Development and Maintenance SAMA CSF 2.2.4 - Access Control and Authentication
🟡 ISO 27001:2022
ISO 27001:2022 A.5.23 - Web application security ISO 27001:2022 A.8.2.3 - Segregation of duties ISO 27001:2022 A.8.3.1 - User registration and access provisioning ISO 27001:2022 A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
PCI DSS 6.5.7 - Cross-site scripting (XSS) prevention PCI DSS 6.2 - Security patches and updates PCI DSS 11.3 - Penetration testing
📦 Affected Products / CPE 3 entries
tiny:tinymce
tiny:tinymce
tiny:tinymce
📊 CVSS Score
8.7
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionR — Required
ScopeC — Changed
ConfidentialityH — High
IntegrityH — High
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score8.7
CWECWE-79
EPSS0.03%
Exploit No
Patch ✓ Yes
Published 2026-05-28
Source Feed nvd
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
patch-available CWE-79
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.