TinyMCE 8.9.3
| These are the Tiny Cloud and TinyMCE Enterprise release notes. For information on the latest community version of TinyMCE, see the TinyMCE Changelog. |
Overview
TinyMCE 8.9.3 was released for TinyMCE Enterprise and Tiny Cloud on Tuesday, October 6th, 2026. These release notes provide an overview of the changes for TinyMCE 8.9.3, including:
Security fixes
TinyMCE 8.9.3 includes a fix for the following security issue:
Fixed stored XSS vulnerability using media plugin data-mce-object serialization
A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Elements crafted through the data-mce-object attribute were created before sanitization, which allowed event handler scripts on those elements to run. TinyMCE 8.9.3 ensures that, when the media plugin is in use, any content created through the data-mce-object attribute is sanitized first.
CVE: pending
GHSA: GitHub Advisories.
| Tiny Technologies would like to thank Fariskhi Vidyan and David Vieira Kurz (HiSolutions AG) for discovering this vulnerability. |