next-tinacms-azure vulnerabilities
CVEs whose affected-version data names the next-tinacms-azure package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-63506High· 8.8PoCTina is a headless content management system
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…
▾ Midnighttinacms · tinacmsEPSS 0.49%via NVD
CVE-2026-59992Medium· 5.4Tina is a headless content management system
Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled obj…
▾ Sunlitnext-tinacms-s3 · next-tinacms-s3EPSS 0.34%via NVD