CRITICAL
10.0 CVE-2026-59167 Published 23 Sept 2026
SunEditor WYSIWYG Editor Stored XSS Vulnerability
Worried this affects your website?
SunEditor, a lightweight WYSIWYG editor written in vanilla JavaScript, contains a stored cross-site scripting vulnerability prior to version 2.47.11.
The sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements.
- Affected versions: before 2.47.11
- Fixed version: 2.47.11
- Impact: script execution in the application's browser origin, data exposure, or unauthorized browser-context actions when a user interacts with the element
Reference: CVE-2026-59167 on NVD
← Back to Security News