← Back to search

CVE-2026-59167

10 CRITICALpublic exploit available

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
The flaw in SunEditor allows event-handler attributes to remain on crafted elements, enabling stored cross-site scripting and potentially leading to data exposure or unauthorized actions.
Exploitability
Exploitation is moderately hard as it requires crafting specific HTML elements with event handlers, but preconditions include the application rendering attacker-controlled content.
Blast radius
If exploited, this could lead to significant data exposure or unauthorized actions within the application's browser context, impacting user data and application integrity.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 2.47.11 or later.
xsswebeditorsanitization

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-79

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.