Stored Cross-Site Scripting Vulnerability in SunEditor by JiHong88
CVE-2026-59167

10CRITICAL

Key Information:

Vendor

Jihong88

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-59167?

A stored cross-site scripting vulnerability exists in SunEditor, an effective WYSIWYG editor. Prior to version 2.47.11, the editor’s sanitizer fails to consistently reject namespaced or custom HTML elements, allowing attacker-controlled event-handler attributes on crafted elements. This can result in malicious scripts being executed within the application's browser context when a user interacts with the manipulated editor content. The issue has been resolved in version 2.47.11, and users are advised to update their installations immediately to mitigate potential data exposure and unauthorized actions.

Affected Version(s)

suneditor < 2.47.11

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.