Products: 3
    Vulnerabilities: 11
    Known Exploited: 0
    1
    Critical Level Threats
    8
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-34603

    @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions

    Last Modified: Apr 08, 2026
    Published: Apr 01, 2026

    CVE-2026-34604

    @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions

    Last Modified: Apr 08, 2026
    Published: Apr 01, 2026

    CVE-2026-33949

    @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

    Last Modified: Apr 08, 2026
    Published: Apr 01, 2026

    CVE-2026-29066

    Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI

    Last Modified: Mar 20, 2026
    Published: Mar 12, 2026

    CVE-2026-28791

    Path Traversal in Media Upload Handle in Tina

    Last Modified: Mar 20, 2026
    Published: Mar 12, 2026
    Items Per Page