Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

tinacms — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting tinacms. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TinaCMS is a headless CMS enabling content editing within React applications. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with seven CVEs recorded. Security concerns often stem from improper input validation and insufficient access controls. While no major public security incidents have been widely reported, the presence of multiple CVEs indicates potential risks for implementations. Users should ensure proper configuration and timely updates to mitigate these vulnerabilities. The platform's integration with frontend frameworks creates unique attack surfaces that require careful security considerations during deployment and maintenance.

Top products by tinacms: tinacms
CVE ID Title CVSS Severity Published
CVE-2026-63506 Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site — tinacms CWE-639 8.8 High 2026-09-16
CVE-2026-63123 Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root — tinacms CWE-352 6.5 Medium 2026-08-19
CVE-2026-59992 Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) — tinacms CWE-639 5.4 Medium 2026-08-19
CVE-2026-55660 TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover — tinacms CWE-79 - - 2026-07-01
CVE-2026-54074 @tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels — tinacms CWE-94 7.8 High 2026-07-01
CVE-2026-55661 TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes — tinacms CWE-79 - - 2026-07-01
CVE-2026-34603 @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions — tinacms CWE-22 7.1 High 2026-04-01
CVE-2026-34604 @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions — tinacms CWE-22 7.1 High 2026-04-01
CVE-2026-33949 @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files — tinacms CWE-22 8.1 High 2026-04-01
CVE-2026-28791 Path Traversal in Media Upload Handle in Tina — tinacms CWE-22 7.4 High 2026-03-12
CVE-2025-68278 tinacms vulnerable to arbitrary code execution — tinacms CWE-94 9.8AI Critical AI 2025-12-18
CVE-2024-45391 Tina search token leak via lock file in TinaCMS — tinacms CWE-200 7.5 High 2024-09-03
CVE-2023-25164 Sensitive Information leak via Script File in TinaCMS — tinacms CWE-532 8.6 High 2023-02-08

This page lists every published CVE security advisory associated with tinacms. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.