As part of the October 2024 security patch cycle (APSB24-73), Adobe upgraded the bundled TinyMCE editor to version 7.3. It closes CVE-2024-38357 and brings the editor your content team uses every day up to date.
Where TinyMCE sits
TinyMCE is the rich-text editor used throughout Adobe Commerce (Magento): product descriptions, CMS content, email templates, marketing material. Merchants, content teams and marketers are in it daily, which is exactly why its security matters.
CVE-2024-38357
The vulnerability fixed in TinyMCE 7.3 relates to XSS (cross-site scripting) through the editor interface. In certain circumstances an attacker could inject malicious scripts via the editor, potentially compromising merchant accounts or stealing sensitive data. It is a particular concern in multi-user environments where a lot of people have editor access.
What changes for you
The upgrade comes along with the Adobe Commerce security patches — you do not apply it separately. It is backward compatible: existing editor configurations keep working without modification, and content created in previous versions displays correctly in 7.3.
Beyond the fix, 7.3 is faster, has better mobile support and improves accessibility. Content teams should find the editing experience smoother across devices.
Worth testing
Run your content editing workflows after patching. The upgrade is generally transparent, but if you have custom plugins or toolbar customisations, check those specifically.
Vulnerabilities keep being found and keep being patched. Staying current means you get the fixes as they land. Sitting on an old version means the vulnerability becomes public knowledge while the patch stays out of reach.
:quality(75))