tinacms has 5 CVEs on record. 2 were published in the last 90 days. The busiest recent month was June 2026 with 3. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: tinacms (3), @tinacms/cli (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 2 prev 3
Worst active — by depth score
CVE-2026-63506High· 8.8Tina is a headless content management system60CVE-2026-54074High· 7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels43CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover41CVE-2026-63123Medium· 6.5Tina is a headless content management system36CVE-2026-55661MediumTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes28
tinacms vulnerabilities
CVEs affecting tinacms, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-63506High· 8.8PoCTina is a headless content management system
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…
CVE-2026-63123Medium· 6.5Tina is a headless content management system
Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, an…
CVE-2026-54074High· 7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
CVE-2026-55661MediumTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes