Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions modules/ROOT/nav.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -417,6 +417,9 @@
** xref:tinymce-and-cors.adoc[Cross-Origin Resource Sharing (CORS)]
* Release information
** xref:release-notes.adoc[Release notes for {productname}]
*** {productname} 7.9.4
**** xref:7.9.4-release-notes.adoc#overview[Overview]
**** xref:7.9.4-release-notes.adoc#security-fixes[Security fixes]
*** {productname} 7.9.3
**** xref:7.9.3-release-notes.adoc#overview[Overview]
**** xref:7.9.3-release-notes.adoc#security-fixes[Security fixes]
Expand Down
33 changes: 33 additions & 0 deletions modules/ROOT/pages/7.9.4-release-notes.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
= {productname} {release-version}
:release-version: 7.9.4
:navtitle: {productname} {release-version}
:description: Release notes for {productname} {release-version}
:keywords: releasenotes, new, changes, bugfixes
:page-toclevels: 1

include::partial$misc/admon-releasenotes-for-stable.adoc[]


[[overview]]
== Overview

{productname} {release-version} was released for {enterpriseversion} and {cloudname} on Tuesday, October 6^th^, 2026. These release notes provide an overview of the changes for {productname} {release-version}, including:

* xref:security-fixes[Security fixes]


[[security-fixes]]
== Security fixes

{productname} {release-version} includes a fix for the following security issue:

=== Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization
// #TINYMCE-14932

A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Elements crafted through the `data-mce-object` attribute were created before sanitization, which allowed event handler scripts on those elements to run. {productname} {release-version} ensures that, when the media plugin is in use, any content created through the `data-mce-object` attribute is sanitized first.

CVE: _pending_

GHSA: https://github.com/tinymce/tinymce/security/advisories/GHSA-mf2p-h6hf-fcwm[GitHub Advisories].

NOTE: Tiny Technologies would like to thank https://github.com/farisv[Fariskhi Vidyan] and David Vieira Kurz (HiSolutions AG) for discovering this vulnerability.
7 changes: 7 additions & 0 deletions modules/ROOT/pages/changelog.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,13 @@

NOTE: This is the {productname} Community version changelog. For information about the latest {cloudname} or {enterpriseversion} Release, see: xref:release-notes.adoc[{productname} Release Notes].

== xref:7.9.4-release-notes.adoc[7.9.4 - 2026-10-06]

=== Security

* Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization.
// #TINYMCE-14932

== xref:7.9.3-release-notes.adoc[7.9.3 - 2026-05-20]

=== Security
Expand Down
8 changes: 7 additions & 1 deletion modules/ROOT/pages/release-notes.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ This section lists the releases for {productname} 7 and the changes made in each
[cols="1,1"]
|===

a|
[.lead]
xref:7.9.4-release-notes.adoc#overview[{productname} 7.9.4]

Release notes for {productname} 7.9.4

a|
[.lead]
xref:7.9.3-release-notes.adoc#overview[{productname} 7.9.3]
Expand Down Expand Up @@ -136,6 +142,6 @@ xref:7.0-release-notes.adoc#overview[{productname} 7.0.0]
Release notes for {productname} 7.0.0

// Uncomment this dummy cell when the number of cells above is odd to ensure the table renders correctly.
a|
// a|

|===
Loading