Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions modules/ROOT/nav.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -422,6 +422,9 @@
** xref:tinymce-and-cors.adoc[Cross-Origin Resource Sharing (CORS)]
* Release information
** xref:release-notes.adoc[Release notes for {productname}]
*** {productname} 8.9.3
**** xref:8.9.3-release-notes.adoc#overview[Overview]
**** xref:8.9.3-release-notes.adoc#security-fixes[Security fixes]
*** {productname} 8.9.2
**** xref:8.9.2-release-notes.adoc#overview[Overview]
**** xref:8.9.2-release-notes.adoc#accompanying-premium-plugin-changes[Accompanying Premium Plugin changes]
Expand Down
33 changes: 33 additions & 0 deletions modules/ROOT/pages/8.9.3-release-notes.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
= {productname} {release-version}
:release-version: 8.9.3
:navtitle: {productname} {release-version}
:description: Release notes for {productname} {release-version}
:keywords: releasenotes, new, changes, bugfixes
:page-toclevels: 1

include::partial$misc/admon-releasenotes-for-stable.adoc[]


[[overview]]
== Overview

{productname} {release-version} was released for {enterpriseversion} and {cloudname} on Tuesday, October 6^th^, 2026. These release notes provide an overview of the changes for {productname} {release-version}, including:

* xref:security-fixes[Security fixes]


[[security-fixes]]
== Security fixes

{productname} {release-version} includes a fix for the following security issue:

=== Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization
// #TINYMCE-14932

A stored cross-site scripting (XSS) vulnerability was identified in the media plugin. Elements crafted through the `data-mce-object` attribute were created before sanitization, which allowed event handler scripts on those elements to run. {productname} {release-version} ensures that, when the media plugin is in use, any content created through the `data-mce-object` attribute is sanitized first.

CVE: _pending_

GHSA: https://github.com/tinymce/tinymce/security/advisories/GHSA-mf2p-h6hf-fcwm[GitHub Advisories].

NOTE: Tiny Technologies would like to thank https://github.com/farisv[Fariskhi Vidyan] and David Vieira Kurz (HiSolutions AG) for discovering this vulnerability.
7 changes: 7 additions & 0 deletions modules/ROOT/pages/changelog.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,13 @@

NOTE: This is the {productname} Community version changelog. For information about the latest {cloudname} or {enterpriseversion} Release, see: xref:release-notes.adoc[{productname} Release Notes].

== xref:8.9.3-release-notes.adoc[8.9.3 - 2026-10-06]

=== Security

* Fixed stored XSS vulnerability using media plugin `data-mce-object` serialization.
// #TINYMCE-14932

== xref:8.9.2-release-notes.adoc[8.9.2 - 2026-09-23]

NOTE: This release contains fixes for Premium plugins only and does not include any changes to the core {productname} editor.
Expand Down
8 changes: 7 additions & 1 deletion modules/ROOT/pages/release-notes.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ This section lists the releases for {productname} {productmajorversion} and the

[cols="1,1"]
|===
a|
[.lead]
xref:8.9.3-release-notes.adoc#overview[{productname} 8.9.3]

Release notes for {productname} 8.9.3

a|
[.lead]
xref:8.9.2-release-notes.adoc#overview[{productname} 8.9.2]
Expand Down Expand Up @@ -147,5 +153,5 @@ xref:8.0-release-notes.adoc#overview[{productname} 8.0.0]
Release notes for {productname} 8.0.0

// Uncomment the dummy cell when the number of cells in the table is odd to ensure the table renders correctly.
a|
// a|
|===
Loading