Ssw maintains TinaCMS, a modestly represented but prominent headless content-management system and its supporting CLI and GraphQL components. Vulnerabilities affecting this vendor center on file-system and information-disclosure issues, with recurring weaknesses including path traversal, improper link resolution, exposure of sensitive data in cleartext, and external control of file paths—attack vectors characteristic of systems handling user-supplied content and file operations. Defenders tracking this vendor should focus on content-pipeline isolation and input validation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ssw over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29066MEDIUM Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem acc | Mar 12, 2026 | 6.2 | 33 | NO | YES |
CVE-2026-28792CRITICAL Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path tr | Mar 12, 2026 | 9.6 | 32 | NO | NO |
CVE-2025-68278HIGH Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the con | Dec 18, 2025 | 8.8 | 32 | NO | NO |
CVE-2026-34604HIGH Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversa | Apr 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-33949HIGH Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitra | Apr 1, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-28793HIGH Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers t | Mar 12, 2026 | 8.4 | 28 | NO | NO |
CVE-2026-34603HIGH Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation stil | Apr 1, 2026 | 8.3 | 27 | NO | NO |
CVE-2026-28791HIGH Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts j | Mar 12, 2026 | 7.4 | 24 | NO | NO |
CVE-2023-25164HIGH Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in | Feb 8, 2023 | 7.5 | 24 | NO | NO |
CVE-2026-24125MEDIUM Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelat | Mar 12, 2026 | 6.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ssw.
Media articles that mention a CVE ID that affects a product developed by Ssw — matched by CVE ID, not by vendor name.