Products: 2
    Vulnerabilities: 14
    Known Exploited: 0
    1
    Critical Level Threats
    7
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-63123

    Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root

    Last Modified: Aug 25, 2026
    Published: Aug 19, 2026

    CVE-2026-59992

    Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)

    Last Modified: Aug 21, 2026
    Published: Aug 19, 2026

    CVE-2026-55660

    TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

    Last Modified: Jul 29, 2026
    Published: Jul 01, 2026

    CVE-2026-54074

    @tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

    Last Modified: Jul 29, 2026
    Published: Jul 01, 2026

    CVE-2026-55661

    TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

    Last Modified: Jul 29, 2026
    Published: Jul 01, 2026
    Items Per Page