TinyMCE 7.3 lands in the October security patches

October's Adobe Commerce security patches upgrade TinyMCE to version 7.3, addressing CVE-2024-38357 across all supported release lines.

Adobe's October 2024 security patches upgrade TinyMCE — the rich text editor built into Adobe Commerce (Magento) — to version 7.3. The upgrade addresses CVE-2024-38357, and it applies across all supported release lines.

What it covers

CVE-2024-38357 sits in the editor's core functionality, which means it is reachable anywhere your team writes content: product descriptions, CMS pages, blocks. TinyMCE 7.3 patches it, and brings the editor's own code stability and performance work along with it.

Adobe has applied the patch across every supported version, so whichever release line you are on, the fix exists for you. Nobody is waiting on a backport.

What to do

Apply the October security patches. If your implementation customises TinyMCE — custom plugins, toolbar changes, an integration that injects content into the editor — test in a staging environment first. A major editor version is exactly the kind of upgrade that finds the customisations you had forgotten about.

For everyone else this is a routine patch on a routine cadence. The editor keeps working, and one more known vulnerability stops being yours to carry.