---
title: "TinyMCE 7.9.3"
description: "Release notes for TinyMCE 7.9.3"
canonical_url: "https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/"
md_url: "https://www.tiny.cloud/docs/tinymce/7/7.9.3-release-notes/index.md"
version: "7"
last_updated: "2026-05-22T02:56:33Z"
tokens: 851
---
Important This page documents TinyMCE 7. For new projects, Tiny recommends using the latest, most up-to-date version. [See TinyMCE 8 documentation](../../latest/).
# TinyMCE 7.9.3

> **Note:** These are the Tiny Cloud and TinyMCE Enterprise release notes. For information on the latest community version of TinyMCE, see the [TinyMCE Changelog](../changelog/).

## Overview

TinyMCE 7.9.3 was released for TinyMCE Enterprise and Tiny Cloud on Wednesday, May 20 th, 2026. These release notes provide an overview of the changes for TinyMCE 7.9.3, including:

- [Security fixes](#security-fixes)

## Security fixes

TinyMCE 7.9.3 includes fixes for the following security issues:

### Fixed stored XSS vulnerability using media plugin `data-mce-object` injection

A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Malicious scripts could be injected through crafted `data-mce-object` and `data-mce-p-` **attributes, which were executed when content was rendered. TinyMCE 7.9.3 ensures that content with `data-mce-object` and `data-mce-p-`** attributes is properly sanitized when the media plugin is in use.

CVE: [CVE-2026-47761](https://nvd.nist.gov/vuln/detail/CVE-2026-47761)

GHSA: [GitHub Advisories](https://github.com/tinymce/tinymce/security/advisories/GHSA-vg35-5wq7-3x7w).

> **Note:** Tiny Technologies would like to thank [Aymane MAZGUITI](https://github.com/UncleJ4ck) and [Ange Primiterra](https://github.com/ange-primiterra) for discovering this vulnerability.

### Fixed stored XSS vulnerability through `mce:protected` comments

A stored cross-site scripting (XSS) vulnerability was identified through forged `mce:protected` comments. Attackers could bypass sanitization and inject scripts that executed when content was restored. This issue affected configurations using the `protect` option. TinyMCE 7.9.3 validates decoded `mce:protected` content against configured `protect` regex rules before restoring.

CVE: [CVE-2026-47762](https://nvd.nist.gov/vuln/detail/CVE-2026-47762)

GHSA: [GitHub Advisories](https://github.com/tinymce/tinymce/security/advisories/GHSA-v98h-vmpc-fpqv).

> **Note:** Tiny Technologies would like to thank [Ivan Babenko (he1d3n)](https://github.com/he1d3n) for discovering this vulnerability.

### Fixed stored XSS vulnerability through `data-mce-` prefixed `src`, `href`, `style` attributes

A stored cross-site scripting (XSS) vulnerability was identified through unsanitized `data-mce-href`, `data-mce-src`, and `data-mce-style` attributes. Malicious values in these attributes could override safe attributes during serialization, bypassing validation. TinyMCE 7.9.3 strips unsafe `data-mce-*` attributes during parsing.

CVE: [CVE-2026-47759](https://nvd.nist.gov/vuln/detail/CVE-2026-47759)

GHSA: [GitHub Advisories](https://github.com/tinymce/tinymce/security/advisories/GHSA-q742-qvgc-gc2f).

> **Note:** Tiny Technologies would like to thank [Tadi Kadango](https://github.com/mtrill47) ([website](https://tadiwakadango.com/)) and [Ivan Babenko (he1d3n)](https://github.com/he1d3n) for discovering this vulnerability.
