A vulnerability classified as problematic was found in TinyMCE up to 5.11.0/6.8.6/7.9.2/8.5.0. This affects an unknown part. The manipulation results in cross site scripting.

This vulnerability is identified as CVE-2026-47761. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.