NES for TinyMCE Release Notes
Comprehensive release notes and changelog for NES for TinyMCE, including security patches, bug fixes, and feature updates across all supported versions.
29 Patched Vulnerabilities
VEX Statements
v6.8.12 - September 23, 2026
Notes
- This release updates the bundled DOMPurify dependency to remediate reported vulnerabilities.
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.6-tinymce-6.8.12
Dependency Updates
- Upgrade
dompurifyto v3.4.16.- Check the
dompurifyrelease notes for details. - This fixes a low-severity vulnerability (GHSA-p98j-92pf-mc4p).
- This fixes a low-severity vulnerability (GHSA-6688-9rhm-gjv2).
- Check the
v6.8.11 - August 4, 2026
Notes
- This release updates the bundled DOMPurify dependency to remediate a reported vulnerability.
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.6-tinymce-6.8.11
Dependency Updates
- Upgrade
dompurifyto v3.4.13.- Check the
dompurifyrelease notes for details. - This fixes a low-severity vulnerability (GHSA-55q2-fjhq-7xh7).
- Check the
v6.8.10 - July 20, 2026
Notes
- This release updates the bundled DOMPurify dependency to remediate a reported vulnerability.
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.6-tinymce-6.8.10
Dependency Updates
- Upgrade
dompurifyto v3.4.12.- Check the
dompurifyrelease notes for details. - This fixes a low-severity vulnerability (GHSA-c2j3-45gr-mqc4).
- Check the
v6.8.9 - July 2, 2026
Notes
- This release backports four security fixes and updates two dependencies to remediate vulnerabilities.
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.6-tinymce-6.8.9
Dependency Updates
- Upgrade
dompurifyto v3.4.11.- Check the
dompurifyrelease notes for details. - This fixes a medium-severity vulnerability (CVE-2025-15599).
- This fixes a medium-severity vulnerability (CVE-2025-26791).
- This fixes a medium-severity vulnerability (CVE-2026-0540).
- This fixes a medium-severity vulnerability (CVE-2026-41238).
- This fixes a medium-severity vulnerability (CVE-2026-41239).
- This fixes a medium-severity vulnerability (CVE-2026-41240).
- This fixes a medium-severity vulnerability (CVE-2026-49458).
- This fixes a medium-severity vulnerability (CVE-2026-49459).
- This fixes a medium-severity vulnerability (CVE-2026-49978).
- This fixes a medium-severity vulnerability (CVE-2026-65914).
- This fixes a medium-severity vulnerability (CVE-2026-65913).
- This fixes a medium-severity vulnerability (CVE-2026-65912).
- This fixes a medium-severity vulnerability (CVE-2026-65903).
- This fixes a medium-severity vulnerability (CVE-2026-65902).
- This fixes a low-severity vulnerability (CVE-2026-65900).
- This fixes a low-severity vulnerability (CVE-2026-65899).
- This fixes a medium-severity vulnerability (CVE-2026-65898).
- This fixes a low-severity vulnerability (CVE-2026-65901).
- Check the
- Upgrade
prismjsto v1.30.0.- Check the
prismjsrelease notes for details. - This fixes a medium-severity vulnerability (CVE-2024-53382).
- Check the
Security Fixes
data-mce-*attribute handling: maliciousdata-mce-src,data-mce-href, anddata-mce-styleattributes supplied in input are now nulled during parsing.- This fixes a high-severity stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-47759).
- SVG namespace tracking: nested
<svg>elements no longer corrupt the sanitizer's namespace scope.- This fixes a high-severity Cross-Site Scripting (XSS) vulnerability (CVE-2026-47760).
mediaplugin serialization: media placeholder attributes (data-mce-objectanddata-mce-p-*) are now sanitized when reconstructing live media elements.- This fixes a high-severity stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-47761).
- Protected-comment restoration:
<!--mce:protected ...-->comments are now decoded only when theprotectoption is configured and the decoded content fully matches a configuredprotectpattern.- This fixes a high-severity stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-47762).
v6.8.8 - August 26, 2025
Notes
- This release contains no functional change from the OSS tinymce v6.8.6.
- This release mainlines OSS v6.8.6 into NES v6.8.8.
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.6-tinymce-6.8.8
v6.8.7 - June 13, 2025
Notes
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.5-tinymce-6.8.7
Security Fixes
convert_unsafe_embedseditor option: now defaulted totrue.- This fixes a medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2024-29881).
sandbox_iframeseditor option: now defaulted totrue.- This fixes a medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2024-29203).
sandbox_iframes_exclusionsoption: new option holding a list of URL host names to be excluded from iframe sandboxing whensandbox_iframesis set totrue.- This fixes a medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2024-29203).
v6.8.6 - June 12, 2025
Notes
- This release contains no functional change from the OSS tinymce v6.8.5.
- This release mainlines OSS v6.8.5 into NES v6.8.6.
- Full package name(s) and version(s):
@neverendingsupport/tinymce@6.8.5-tinymce-6.8.6