CVE-2026-59167

LOWCVSS 10.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-09-24: 409-24
Referenced assets2 URLs
Full discourse4 posts
  • ExploitGrid@exploitgrid

    [CVE] CVE-2026-59167 [HIGH PRIORITY] #SunEditor: Critical XSS vulnerability - sanitizer bypass 🔗 https://exploitgrid.net/cve/CVE-2026-59167

    1000039
    47 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-59167 CVE-2026-86708 CVE-2026-96257 CVE-2026-19599 CVE-2026-77602 ..🧵👇

    1000044
    47 followersView on X
  • ExploitGrid@exploitgrid

    🟠 HIGH PRIORITY ├ CVE-2026-59167 — SunEditor · XSS sanitizer bypass ├ CVE-2026-86708 — Sensitive data exposure ├ CVE-2026-96257 — Fast FAC1203R · Stack overflow ├ CVE-2026-19599 — Remote Code Execution └ CVE-2026-77602 — OpenC3 COSMOS · Auth'd RCE via writable config

    1000038
    47 followersView on X
  • DailyCVE@dailycve

    🔴 SunEditor, Stored XSS via Namespaced Element Sanitizer Bypass, #CVE-2026-59167 (Critical) -DC-Sep2026-2558 https://dailycve.com/suneditor-stored-xss-via-namespaced-element-sanitizer-bypass-cve-2026-59167-critical-dc-sep2026-2558/

    0000041
    237 followersView on X

Explore more