A critical vulnerability affecting suneditor versions Confirmed vulnerable:, designated as CVE-2026-59167 with a CVSS score of 10.0, affects SunEditor versions less than or equal to 2.47.10. This flaw is categorized as CWE-79 and allows attackers to inject arbitrary JavaScript into rendered editor content, potentially leading to stored XSS, DOM manipulation, session theft, credential theft, and account takeover actions performed in the victim's browser context. The vulnerability arises from incomplete sanitization logic that fails to remove executable event-handler attributes from certain custom/namespaced tags, enabling an attacker to execute malicious code when the rendered element is interacted with. Depending on how SunEditor is integrated into an application, this could result in severe business impact, including compromised user sessions and stolen credentials.
We recommend you to upgrade SunEditor to version 2.47.11 or later.[/subscribe_to_unlock_form]
A critical vulnerability affecting suneditor versions Confirmed vulnerable:, designated as CVE-2026-59167 with a CVSS score of 10.0, affects SunEditor versions less than or equal to 2.47.10. This flaw is categorized as CWE-79 and allows attackers to inject arbitrary JavaScript into rendered editor content, potentially leading to stored XSS, DOM manipulation, session theft, credential theft, and account takeover actions performed in the victim's browser context. The vulnerability arises from incomplete sanitization logic that fails to remove executable event-handler attributes from certain custom/namespaced tags, enabling an attacker to execute malicious code when the rendered element is interacted with. Depending on how SunEditor is integrated into an application, this could result in severe business impact, including compromised user sessions and stolen credentials.
We recommend you to upgrade SunEditor to version 2.47.11 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]