Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tinacms\/graphql HIGH 8.8
CVE-2026-34604

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge.…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Tinacms\/cli HIGH 8.3
CVE-2026-34603

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media rout…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Tinacms\/graphql HIGH 8.1
CVE-2026-33949

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Tinacms\/cli CRITICAL 9.6
CVE-2026-28792

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al…

Fix: 2.1.8+
Fix from $2,300 2026-03-12
Tinacms\/cli HIGH 8.4
CVE-2026-28793

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path …

Fix: 2.1.8+
Fix from $1,950 2026-03-12
Tinacms\/cli HIGH 7.4
CVE-2026-28791

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload …

Fix: 2.1.7+
Fix from $1,950 2026-03-12
Tinacms\/cli MEDIUM 6.2
CVE-2026-29066

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables…

Fix: 2.1.8+
Fix from $1,600 2026-03-12
Tinacms\/graphql MEDIUM 6.3
CVE-2026-24125

Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative fil…

Fix: 2.1.2+
Fix from $1,600 2026-03-12
Tinacms HIGH 8.8
CVE-2025-68278

Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing att…

Fix: 2.0.3 / 2.0.4+
Fix from $1,950 2025-12-18
Tinacms\/cli HIGH 7.5
CVE-2024-45391

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a…

Fix: 1.6.2+
Fix from $1,950 2024-09-03
Tinacms\/cli HIGH 7.5
CVE-2023-25164

Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 w…

Fix: 1.0.9+
Fix from $1,950 2023-02-08