#11247·tinymce

Update DomPurify to Version 3.4.13/3.4.14

Author: cfritzCreated Sep 1, 2026Updated Sep 4, 2026
Labelstype: bug

Provide detailed reproduction steps (if any)

The dependency scanner is flagging TinyMCE for containing a vulnerable version of DOMPurify.

✔️ Expected result

The DOMPurify version embedded into TinyMCE should have no known vulnerabilities.

❌ Actual result

The following vulnerability is flagged: https://nvd.nist.gov/vuln/detail/cve-2026-75838

❓ Possible solution

Would it be possible to update to version 3.4.13 or 3.4.14

Thank you very much in advance :)