Products: 2
Vulnerabilities: 14
Known Exploited: 0
1
Critical Level Threats
7
High Level Threats
4
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-63123
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
Last Modified: Aug 25, 2026
Published: Aug 19, 2026
CVE-2026-59992
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
Last Modified: Aug 21, 2026
Published: Aug 19, 2026
CVE-2026-55660
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
Last Modified: Jul 29, 2026
Published: Jul 01, 2026
CVE-2026-54074
@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
Last Modified: Jul 29, 2026
Published: Jul 01, 2026
CVE-2026-55661
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
Last Modified: Jul 29, 2026
Published: Jul 01, 2026
Items Per Page
