Vulnerabilities in tinacms
13 resultsVexday analysis
TinaCMS apresenta 10 vulnerabilidades catalogadas, com 3 descobertas nos últimos 90 dias, indicando risco moderado e ativo. Nenhuma CVE está sob exploração conhecida (KEV) e não há críticas, mas a fraqueza dominante é CWE-22 (traversal de diretório), um vetor clássico de comprometimento de integridade de conteúdo. O padrão recente de descobertas sugere superfície de ataque em análise contínua.
CVE-2023-25164HIGHSensitive Information leak via Script File in TinaCMSEPSS 0.7%CVE-2026-63506HIGHTina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted siteEPSS 0.5%CVE-2025-68278HIGHtinacms vulnerable to arbitrary code executionEPSS 0.5%CVE-2026-34603HIGH@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or JunctionsEPSS 0.4%CVE-2026-55661MEDIUMTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemesEPSS 0.4%CVE-2026-33949HIGH@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesEPSS 0.4%CVE-2026-34604HIGH@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or JunctionsEPSS 0.4%CVE-2026-59992MEDIUMTina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)EPSS 0.3%CVE-2026-28791HIGHPath Traversal in Media Upload Handle in TinaEPSS 0.3%CVE-2024-45391HIGHTina search token leak via lock file in TinaCMSEPSS 0.3%CVE-2026-55660HIGHTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeoverEPSS 0.3%CVE-2026-54074HIGH@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labelsEPSS 0.3%CVE-2026-63123MEDIUMTina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media rootEPSS 0.2%