VYPR
Vendor

TinaCMS

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2023-25164HigFeb 8, 2023
    risk 0.49cvss 8.6epss 0.01

    Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js…

  • CVE-2026-54074HigJul 1, 2026
    risk 0.44cvss 7.8epss 0.00

    Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-Tina migration command. The internal helper addVariablesToCode unquotes any value matching the marker…

  • CVE-2024-45391HigSep 3, 2024
    risk 0.42cvss 7.5epss 0.00

    Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled…

  • CVE-2026-28791HigMar 12, 2026
    risk 0.41cvss 7.4epss 0.00

    Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path…

  • CVE-2026-63123MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugi…

  • CVE-2026-59992MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete…

  • CVE-2026-55661MedJul 1, 2026
    risk 0.24cvss epss 0.00

    Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs —…