📝 Provide detailed reproduction steps (if any)
The dependency scanner is flagging TinyMCE for containing a vulnerable version of DOMPurify.
✔️ Expected result
The DOMPurify version embedded into TinyMCE should have no known vulnerabilities.
❌ Actual result
The following vulnerability is flagged:
https://nvd.nist.gov/vuln/detail/cve-2026-75838
❓ Possible solution
Would it be possible to update to version 3.4.16
Thank you very much in advance :)
📝 Provide detailed reproduction steps (if any)
The dependency scanner is flagging TinyMCE for containing a vulnerable version of DOMPurify.
✔️ Expected result
The DOMPurify version embedded into TinyMCE should have no known vulnerabilities.
❌ Actual result
The following vulnerability is flagged:
https://nvd.nist.gov/vuln/detail/cve-2026-75838
❓ Possible solution
Would it be possible to update to version 3.4.16
Thank you very much in advance :)