Sammy Posted 13 hours ago Posted 13 hours ago Hello, I'm new to this forum, but I work at an agency that uses processwire for most of our bespoke sites. I've started setting up vulnerability scanning on most of our projects and I've discovered that the version of tinyMCE bundled with processwire has some high severity (according to github) vulnerabilities. https://nvd.nist.gov/vuln/detail/cve-2026-47759 https://nvd.nist.gov/vuln/detail/cve-2026-47760 https://nvd.nist.gov/vuln/detail/cve-2026-47761 https://nvd.nist.gov/vuln/detail/cve-2026-47762 These are XSS vulnerabilities so to spell it out this would mean that one admin could steal another admin's session (which I believe is classed as a medium severity issue) or if users can control something that ends up in an admin wysiwyg (idk maybe in a contact form or something) a non-user could steal an admin session (high severity). They were disclosed in May. The big problem is: tinyMCE v6 is end of life, and the new versions have a new licence that is not really compatible with projects like processwire. I've searched the forums and found some discussion of this from a few years ago, but I think I'm the first to raise the subject in a while and perhaps the first to notice these CVEs. Firstly, I guess I'm just disclosing the issue and warning anyone who uses user data in wysiwyg that they cannot trust tinyMCE and should take action. Secondly I have a few questions Is there an alternative rich text editor module anyone can recommend? Is there an alternative rich text editor that does not yet exist as a module anyone can recommend? Are there plans to move off tinyMCE in the future? I appreciate this is going to be a big task.
Sammy Posted 12 hours ago Author Posted 12 hours ago 33 minutes ago, Sammy said: Firstly, I guess I'm just disclosing the issue and warning anyone who uses user data in wysiwyg that they cannot trust tinyMCE and should take action Ah, there is a HTML sanitiser than runs that limits the risk here
Sammy Posted 5 hours ago Author Posted 5 hours ago I have got claude to make a WYSIWYG input field module using jodit, keeping as close as possible to the original TinyMCE integration, I plan to use it temporarily until a longer term fix comes from upstream. I've made it public in case that's an acceptable solution for anyone else. https://github.com/castusdesign/pw-module-inputfield-jodit 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now