diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index fd05240f19..41c5f3f7c7 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -422,6 +422,9 @@ ** xref:tinymce-and-cors.adoc[Cross-Origin Resource Sharing (CORS)] * Release information ** xref:release-notes.adoc[Release notes for {productname}] +*** {productname} 8.9.3 +**** xref:8.9.3-release-notes.adoc#overview[Overview] +**** xref:8.9.3-release-notes.adoc#security-fixes[Security fixes] *** {productname} 8.9.2 **** xref:8.9.2-release-notes.adoc#overview[Overview] **** xref:8.9.2-release-notes.adoc#accompanying-premium-plugin-changes[Accompanying Premium Plugin changes] diff --git a/modules/ROOT/pages/8.9.3-release-notes.adoc b/modules/ROOT/pages/8.9.3-release-notes.adoc new file mode 100644 index 0000000000..2656980249 --- /dev/null +++ b/modules/ROOT/pages/8.9.3-release-notes.adoc @@ -0,0 +1,33 @@ += {productname} {release-version} +:release-version: 8.9.3 +:navtitle: {productname} {release-version} +:description: Release notes for {productname} {release-version} +:keywords: releasenotes, new, changes, bugfixes +:page-toclevels: 1 + +include::partial$misc/admon-releasenotes-for-stable.adoc[] + + +[[overview]] +== Overview + +{productname} {release-version} was released for {enterpriseversion} and {cloudname} on Tuesday, October 6^th^, 2026. These release notes provide an overview of the changes for {productname} {release-version}, including: + +* xref:security-fixes[Security fixes] + + +[[security-fixes]] +== Security fixes + +{productname} {release-version} includes a fix for the following security issue: + +=== Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization +// #TINYMCE-14932 + +A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Elements crafted through the `data-mce-object` attribute were created before sanitization, which allowed event handler scripts on those elements to run. {productname} {release-version} ensures that, when the media plugin is in use, any content created through the `data-mce-object` attribute is sanitized first. + +CVE: _pending_ + +GHSA: https://github.com/tinymce/tinymce/security/advisories/GHSA-mf2p-h6hf-fcwm[GitHub Advisories]. + +NOTE: Tiny Technologies would like to thank https://github.com/farisv[Fariskhi Vidyan] and David Vieira Kurz (HiSolutions AG) for discovering this vulnerability. diff --git a/modules/ROOT/pages/changelog.adoc b/modules/ROOT/pages/changelog.adoc index 037a522bfc..bef8a7d0c7 100644 --- a/modules/ROOT/pages/changelog.adoc +++ b/modules/ROOT/pages/changelog.adoc @@ -5,6 +5,13 @@ NOTE: This is the {productname} Community version changelog. For information about the latest {cloudname} or {enterpriseversion} Release, see: xref:release-notes.adoc[{productname} Release Notes]. +== xref:8.9.3-release-notes.adoc[8.9.3 - 2026-10-06] + +=== Security + +* Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization. +// #TINYMCE-14932 + == xref:8.9.2-release-notes.adoc[8.9.2 - 2026-09-23] NOTE: This release contains fixes for Premium plugins only and does not include any changes to the core {productname} editor. diff --git a/modules/ROOT/pages/release-notes.adoc b/modules/ROOT/pages/release-notes.adoc index 68e86ff7fd..486b6163d1 100644 --- a/modules/ROOT/pages/release-notes.adoc +++ b/modules/ROOT/pages/release-notes.adoc @@ -9,6 +9,12 @@ This section lists the releases for {productname} {productmajorversion} and the [cols="1,1"] |=== +a| +[.lead] +xref:8.9.3-release-notes.adoc#overview[{productname} 8.9.3] + +Release notes for {productname} 8.9.3 + a| [.lead] xref:8.9.2-release-notes.adoc#overview[{productname} 8.9.2] @@ -147,5 +153,5 @@ xref:8.0-release-notes.adoc#overview[{productname} 8.0.0] Release notes for {productname} 8.0.0 // Uncomment the dummy cell when the number of cells in the table is odd to ensure the table renders correctly. -a| +// a| |===