---
title: "TinyMCE 7.9.4"
description: "Release notes for TinyMCE 7.9.4"
canonical_url: "https://www.tiny.cloud/docs/tinymce/7/7.9.4-release-notes/"
md_url: "https://www.tiny.cloud/docs/tinymce/7/7.9.4-release-notes/index.md"
version: "7"
last_updated: "2026-10-06T05:17:16Z"
tokens: 360
---
Important This page documents TinyMCE 7. For new projects, Tiny recommends using the latest, most up-to-date version. [See TinyMCE 8 documentation](../../latest/).
# TinyMCE 7.9.4

> **Note:** These are the Tiny Cloud and TinyMCE Enterprise release notes. For information on the latest community version of TinyMCE, see the [TinyMCE Changelog](../changelog/).

## Overview

TinyMCE 7.9.4 was released for TinyMCE Enterprise and Tiny Cloud on Tuesday, October 6 th, 2026. These release notes provide an overview of the changes for TinyMCE 7.9.4, including:

- [Security fixes](#security-fixes)

## Security fixes

TinyMCE 7.9.4 includes a fix for the following security issue:

### Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization

A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Elements crafted through the `data-mce-object` attribute were created before sanitization, which allowed event handler scripts on those elements to run. TinyMCE 7.9.4 ensures that, when the media plugin is in use, any content created through the `data-mce-object` attribute is sanitized first.

CVE: *pending*

GHSA: [GitHub Advisories](https://github.com/tinymce/tinymce/security/advisories/GHSA-mf2p-h6hf-fcwm).

> **Note:** Tiny Technologies would like to thank [Fariskhi Vidyan](https://github.com/farisv) and David Vieira Kurz (HiSolutions AG) for discovering this vulnerability.
