Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 330 respecto a la semana anterior
Críticas / altas1308▲ 1 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 272 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.52%—Next-tinacms-azureAISupabase AuthAI16/9/202630/9/2026
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any…
AplazadaMedia (6.5)0.26%—SSW TinacmsAI19/8/202610/9/2026
Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes POST /media/upload/*…
AplazadaMedia (5.4)0.38%—Next-tinacms-s3AINext-tinacms-dosAINext-tinacms-azureAINext-tinacms-cloudinaryAI19/8/202618/9/2026
Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the…
AplazadaMedia (4.8)0.40%—Tinacms MDXAISSW TinacmsAI1/7/20266/7/2026
Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text parsing and the default link/image renderers did not sanitize the url field on Slate link/image nodes. Content containing javascript: or data:text/html URLs — including case-variant, whitespace-padded,…
AplazadaAlta (7.6)0.28%—Tinacms APPAISSW TinacmsAI1/7/20262/7/2026
Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin postMessage handlers and a rich-text URL-sanitization bypass enable stored XSS and session takeover. The library registers window message listeners — the useTina overlay handler, the OAuth…
AplazadaAlta (7.8)0.25%—Tinacms CLIAI1/7/20262/7/2026
Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-Tina migration command. The internal helper addVariablesToCode unquotes any value matching the marker "__TINA_INTERNAL__:::(.*?):::" inside the stringified collection…
AnalizadaAlta (8.8)0.54%—SSW Tinacms/graphql1/4/202617/6/2026
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/junction already exists under the allowed content root, a path like…
AnalizadaAlta (8.3)0.46%—SSW Tinacms/cli1/4/202617/6/2026
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation still validates only the path string and does not resolve symlink or junction targets. If a link already exists under the media root, Tina…
AnalizadaAlta (8.1)0.63%—SSW Tinacms/graphql1/4/202617/6/2026
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The impact includes the…
AnalizadaMedia (6.2)0.56%—SSW Tinacms/cli12/3/202617/6/2026
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the host system. This…
AnalizadaAlta (8.4)0.21%—SSW Tinacms/cli12/3/202617/6/2026
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the CLI starts a local…
ModificadaCrítica (9.6)0.63%—SSW Tinacms/cli12/3/202617/6/2026
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate the filesystem,…
AnalizadaAlta (7.4)0.45%—SSW Tinacms/cli12/3/202617/6/2026
Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path stays within the intended media directory.…
AnalizadaMedia (6.3)0.43%—SSW Tinacms/graphql12/3/202617/6/2026
Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.join() without…
AnalizadaAlta (7.3)0.48%—SSW TinacmsSSW Tinacms/cliSSW Tinacms/graphql18/12/202525/9/2026
Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli version 2.0.4, and…
AnalizadaAlta (7.5)0.31%—SSW Tinacms/cli3/9/202417/6/2026
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search setup should rotate…
AnalizadaAlta (7.5)0.68%—SSW Tinacms/cli8/2/202317/6/2026
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js file. If you're on a version prior to 1.0.0…