Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

tinacms — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in tinacms, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for TinaCMS, a popular open-source content management system, focusing on common weakness types and associated tags. It collects security advisories, reported exploits, and technical details covering a comprehensive time range from the project’s inception to the present day, ensuring both historical context and current threat intelligence are available. Readers can use this resource to track TinaCMS vendor advisories and security updates, gain a deeper understanding of specific weakness classes that affect the platform, and look up the product’s complete vulnerability history to assess long-term security trends. The content is organized to help developers, security researchers, and system administrators quickly identify risks, understand the nature of disclosed flaws, and evaluate the impact of past issues on their deployments. By centralizing these details, the page serves as a factual reference point for auditing, patch management, and risk assessment without requiring users to navigate multiple external sources. All information is presented in a structured format to facilitate efficient analysis and decision-making. Users interested in the security posture of TinaCMS will find this aggregation useful for maintaining up-to-date knowledge of known issues and potential exposure vectors. The focus remains strictly on factual reporting and historical tracking, avoiding speculative commentary or promotional language. This approach ensures that the data remains a reliable tool for technical evaluation and security planning across various use cases and integration scenarios.

Vendor: tinacms

CVE ID Title CVSS Severity Published
CVE-2026-108261 TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment CWE-346 9.3 Critical 2026-10-09
CVE-2026-108260 @tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS CWE-79 7.6 High 2026-10-09
CVE-2026-108259 Tina: Code injection via unescaped Git branch name in generated client source CWE-94 8.2 High 2026-10-09
CVE-2026-63506 Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site CWE-639 8.8 High 2026-09-16
CVE-2026-63123 Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root CWE-352 6.5 Medium 2026-08-19
CVE-2026-59992 Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) CWE-639 5.4 Medium 2026-08-19
CVE-2026-55660 TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover CWE-79 - - 2026-07-01
CVE-2026-54074 @tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels CWE-94 7.8 High 2026-07-01
CVE-2026-55661 TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes CWE-79 - - 2026-07-01
CVE-2026-34603 @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions CWE-22 7.1 High 2026-04-01
CVE-2026-34604 @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions CWE-22 7.1 High 2026-04-01
CVE-2026-33949 @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files CWE-22 8.1 High 2026-04-01
CVE-2026-28791 Path Traversal in Media Upload Handle in Tina CWE-22 7.4 High 2026-03-12
CVE-2025-68278 tinacms vulnerable to arbitrary code execution CWE-94 9.8AI Critical AI 2025-12-18
CVE-2024-45391 Tina search token leak via lock file in TinaCMS CWE-200 7.5 High 2024-09-03
CVE-2023-25164 Sensitive Information leak via Script File in TinaCMS CWE-532 8.6 High 2023-02-08

All 16 known CVE vulnerabilities affecting tinacms with full Chinese analysis, references, and POCs where available.