CVE-2025-68278High· 8.8▾ TwilightTina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli version 2.0.4, and @tinacms/graphql version 2.0.3 contain a fix for the issue.
tinacms < 3.1.1tinacms/cli < 2.0.4tinacms/graphql < 2.0.3Upgrade past the affected range:
tinacms 3.1.1tinacms/cli 2.0.4tinacms/graphql 2.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-63506High· 8.8Tina is a headless content management system
CVE-2026-55661MediumTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
CVE-2025-15394Medium· 4.7A vulnerability was detected in iCMS up to 8.0.0
CVE-2025-15393Medium· 6.3A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135