Skip to main content
CRITICAL

CVE-2026-59167

CVSS v3

10

CRITICAL

EPSS Score

0.4 %

exploit probability, as of 2026-09-29

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, dat

Technical details

Published
2026-09-23
Last Modified
2026-09-24

Frequently asked questions

What is CVE-2026-59167?

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, dat

Is CVE-2026-59167 actively exploited?

Active exploitation of CVE-2026-59167 has not been confirmed. Its EPSS score was 0.4% on 2026-09-29, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-59167?

CVE-2026-59167 has a CVSS v3 base score of 10 (CRITICAL severity).

Is CVE-2026-59167 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key