OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-59167

CRITICAL · CVSS 10 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects SunEditor versions prior to 2.47.11, where the sanitizer in the JavaScript library fails to consistently reject namespaced or custom HTML elements, allowing malicious event-handler attributes to persist. This flaw can lead to stored cross-site scripting, data exposure, or unauthorized actions within the browser context when users interact with compromised content. Organizations using SunEditor should prioritize upgrading to version 2.47.11 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59167
Severity
CRITICAL
CVSS
10
EPSS
0.39%
Java

Original NVD Description

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.