Stored Cross-Site Scripting Vulnerability in SunEditor by JiHong88
CVE-2026-59167
10CRITICAL
What is CVE-2026-59167?
A stored cross-site scripting vulnerability exists in SunEditor, an effective WYSIWYG editor. Prior to version 2.47.11, the editor’s sanitizer fails to consistently reject namespaced or custom HTML elements, allowing attacker-controlled event-handler attributes on crafted elements. This can result in malicious scripts being executed within the application's browser context when a user interacts with the manipulated editor content. The issue has been resolved in version 2.47.11, and users are advised to update their installations immediately to mitigate potential data exposure and unauthorized actions.
Affected Version(s)
suneditor < 2.47.11
