VYPR

TinaCMS

by TinaCMS

CVEs (1)

  • CVE-2026-55661Jun 18, 2026
    risk 0.00cvss epss

    TinaCMS rich-text parsing and the default link/image renderers did not sanitize the `url` field on Slate link/image nodes. Content containing `javascript:` or `data:text/html` URLs — including case-variant, whitespace-padded, and control-character-obfuscated forms — is…