Vulnerabilities
Last updated 3 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment | Critical 9.3 | 4 hours ago | 4 hours ago |
|
|
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment | Critical 9.3 | 4 hours ago | 4 hours ago |
|
|
@tinacms/web-components: `tina-markdown` writes rich-text link URLs into `href` without scheme validation, allowing stored XSS | High Risk 7.6 | 4 hours ago | 4 hours ago |
|
|
Tina: Code injection via unescaped Git branch name in generated client source | High Risk 8.2 | 4 hours ago | 4 hours ago |
|
|
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site | High Risk 8.8 | 22 days ago | 22 days ago |
|
|
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site | High Risk 8.8 | 22 days ago | 22 days ago |
|
|
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes | Medium Risk 6.0 | 3 months ago | 29 days ago |
|
|
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes | Medium Risk 6.0 | 3 months ago | 29 days ago |
|
|
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover | High Risk 8.0 | 3 months ago | 29 days ago |
|
|
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover | High Risk 8.0 | 3 months ago | 29 days ago |
|
|
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels | High Risk 7.8 | 3 months ago | 29 days ago |
|
|
Sensitive Information leak via Script File in TinaCMS | High Risk 8.6 | 3 years ago | 29 days ago |
|
|
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) | Medium Risk 5.4 | 1 month ago | 1 month ago |
|
|
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) | Medium Risk 5.4 | 1 month ago | 1 month ago |
|
|
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) | Medium Risk 5.4 | 1 month ago | 1 month ago |
|
|
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) | Medium Risk 5.4 | 1 month ago | 1 month ago |
|
|
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root | Medium Risk 6.5 | 1 month ago | 1 month ago |
|
|
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files | High Risk 8.1 | 6 months ago | 6 months ago |
|
|
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions | High Risk 7.1 | 6 months ago | 6 months ago |
|
|
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions | High Risk 7.1 | 6 months ago | 6 months ago |
|
|
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS | Critical 9.6 | 7 months ago | 6 months ago |
|
|
TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete | High Risk 8.4 | 7 months ago | 6 months ago |
|
|
TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction | Medium Risk 6.2 | 7 months ago | 6 months ago |
|
|
@tinacms/graphql has a Path Traversal issue | Medium Risk 6.3 | 7 months ago | 6 months ago |
|
|
Tina: Path Traversal in Media Upload Handle | High Risk 7.4 | 7 months ago | 6 months ago |
|
|
tinacms is vulnerable to arbitrary code execution | High Risk 8.0 | 9 months ago | 9 months ago |
|
|
tinacms is vulnerable to arbitrary code execution | High Risk 8.0 | 9 months ago | 9 months ago |
|
|
tinacms is vulnerable to arbitrary code execution | High Risk 8.0 | 9 months ago | 9 months ago |
|
|
Tina search token leak via lock file in TinaCMS | High Risk 7.5 | 2 years ago | 2 years ago |
Page 1