VulnSea

tinacms has 5 CVEs on record. 2 were published in the last 90 days. The busiest recent month was June 2026 with 3. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: tinacms (3), @tinacms/cli (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
2 prev 3

Products

  • tinacms 3
  • @tinacms/cli 2
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

tinacms vulnerabilities

CVEs affecting tinacms, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-63506High· 8.8PoC
6d ago

Tina is a headless content management system

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…

Midnighttinacms · tinacmsEPSS 0.49%via NVD
CVE-2026-63123Medium· 6.5
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, an…

Sunlittinacms · @tinacms/cliEPSS 0.22%via NVD
CVE-2026-54074High· 7.8
3mo ago

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

Twilighttinacms · @tinacms/cliEPSS 0.25%via GHSA
CVE-2026-55660High
3mo ago

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

Twilighttinacms · tinacmsEPSS 0.28%via GHSA
CVE-2026-55661Medium
3mo ago

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

Sunlittinacms · tinacmsEPSS 0.40%via GHSA
tinacms vulnerabilities (CVEs) · VulnSea