diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 319afba142..c617768004 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -417,6 +417,9 @@ ** xref:tinymce-and-cors.adoc[Cross-Origin Resource Sharing (CORS)] * Release information ** xref:release-notes.adoc[Release notes for {productname}] +*** {productname} 7.9.4 +**** xref:7.9.4-release-notes.adoc#overview[Overview] +**** xref:7.9.4-release-notes.adoc#security-fixes[Security fixes] *** {productname} 7.9.3 **** xref:7.9.3-release-notes.adoc#overview[Overview] **** xref:7.9.3-release-notes.adoc#security-fixes[Security fixes] diff --git a/modules/ROOT/pages/7.9.4-release-notes.adoc b/modules/ROOT/pages/7.9.4-release-notes.adoc new file mode 100644 index 0000000000..01c8593278 --- /dev/null +++ b/modules/ROOT/pages/7.9.4-release-notes.adoc @@ -0,0 +1,33 @@ += {productname} {release-version} +:release-version: 7.9.4 +:navtitle: {productname} {release-version} +:description: Release notes for {productname} {release-version} +:keywords: releasenotes, new, changes, bugfixes +:page-toclevels: 1 + +include::partial$misc/admon-releasenotes-for-stable.adoc[] + + +[[overview]] +== Overview + +{productname} {release-version} was released for {enterpriseversion} and {cloudname} on Tuesday, October 6^th^, 2026. These release notes provide an overview of the changes for {productname} {release-version}, including: + +* xref:security-fixes[Security fixes] + + +[[security-fixes]] +== Security fixes + +{productname} {release-version} includes a fix for the following security issue: + +=== Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization +// #TINYMCE-14932 + +A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Elements crafted through the `data-mce-object` attribute were created before sanitization, which allowed event handler scripts on those elements to run. {productname} {release-version} ensures that, when the media plugin is in use, any content created through the `data-mce-object` attribute is sanitized first. + +CVE: _pending_ + +GHSA: https://github.com/tinymce/tinymce/security/advisories/GHSA-mf2p-h6hf-fcwm[GitHub Advisories]. + +NOTE: Tiny Technologies would like to thank https://github.com/farisv[Fariskhi Vidyan] and David Vieira Kurz (HiSolutions AG) for discovering this vulnerability. diff --git a/modules/ROOT/pages/changelog.adoc b/modules/ROOT/pages/changelog.adoc index 87350bed6e..3303c7a971 100644 --- a/modules/ROOT/pages/changelog.adoc +++ b/modules/ROOT/pages/changelog.adoc @@ -4,6 +4,13 @@ NOTE: This is the {productname} Community version changelog. For information about the latest {cloudname} or {enterpriseversion} Release, see: xref:release-notes.adoc[{productname} Release Notes]. +== xref:7.9.4-release-notes.adoc[7.9.4 - 2026-10-06] + +=== Security + +* Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization. +// #TINYMCE-14932 + == xref:7.9.3-release-notes.adoc[7.9.3 - 2026-05-20] === Security diff --git a/modules/ROOT/pages/release-notes.adoc b/modules/ROOT/pages/release-notes.adoc index 4848dcd38b..1ccb5797c7 100644 --- a/modules/ROOT/pages/release-notes.adoc +++ b/modules/ROOT/pages/release-notes.adoc @@ -9,6 +9,12 @@ This section lists the releases for {productname} 7 and the changes made in each [cols="1,1"] |=== +a| +[.lead] +xref:7.9.4-release-notes.adoc#overview[{productname} 7.9.4] + +Release notes for {productname} 7.9.4 + a| [.lead] xref:7.9.3-release-notes.adoc#overview[{productname} 7.9.3] @@ -136,6 +142,6 @@ xref:7.0-release-notes.adoc#overview[{productname} 7.0.0] Release notes for {productname} 7.0.0 // Uncomment this dummy cell when the number of cells above is odd to ensure the table renders correctly. -a| +// a| |===