
[CVE] CVE-2026-59167 [HIGH PRIORITY] #SunEditor: Critical XSS vulnerability - sanitizer bypass 🔗 https://exploitgrid.net/cve/CVE-2026-59167
Signal is active with 4 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handler can execute script in the application's browser origin, enabling stored cross-site scripting, data exposure, or unauthorized browser-context actions. This issue is fixed in version 2.47.11.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

[CVE] CVE-2026-59167 [HIGH PRIORITY] #SunEditor: Critical XSS vulnerability - sanitizer bypass 🔗 https://exploitgrid.net/cve/CVE-2026-59167

🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-59167 CVE-2026-86708 CVE-2026-96257 CVE-2026-19599 CVE-2026-77602 ..🧵👇

🟠 HIGH PRIORITY ├ CVE-2026-59167 — SunEditor · XSS sanitizer bypass ├ CVE-2026-86708 — Sensitive data exposure ├ CVE-2026-96257 — Fast FAC1203R · Stack overflow ├ CVE-2026-19599 — Remote Code Execution └ CVE-2026-77602 — OpenC3 COSMOS · Auth'd RCE via writable config

🔴 SunEditor, Stored XSS via Namespaced Element Sanitizer Bypass, #CVE-2026-59167 (Critical) -DC-Sep2026-2558 https://dailycve.com/suneditor-stored-xss-via-namespaced-element-sanitizer-bypass-cve-2026-59167-critical-dc-sep2026-2558/