Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ssw

First CVE: Feb 8, 2023Active for: 3 yearsTotal CVEs: 11
55.9
VTI Score
TOP TARGET

Ssw maintains TinaCMS, a modestly represented but prominent headless content-management system and its supporting CLI and GraphQL components. Vulnerabilities affecting this vendor center on file-system and information-disclosure issues, with recurring weaknesses including path traversal, improper link resolution, exposure of sensitive data in cleartext, and external control of file paths—attack vectors characteristic of systems handling user-supplied content and file operations. Defenders tracking this vendor should focus on content-pipeline isolation and input validation; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ssw over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2023
3 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-29066MEDIUM
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem acc
Mar 12, 20266.233NOYES
CVE-2026-28792CRITICAL
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path tr
Mar 12, 20269.632NONO
CVE-2025-68278HIGH
Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the con
Dec 18, 20258.832NONO
CVE-2026-34604HIGH
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversa
Apr 1, 20268.828NONO
CVE-2026-33949HIGH
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitra
Apr 1, 20268.128NONO
CVE-2026-28793HIGH
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers t
Mar 12, 20268.428NONO
CVE-2026-34603HIGH
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but the implementation stil
Apr 1, 20268.327NONO
CVE-2026-28791HIGH
Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts j
Mar 12, 20267.424NONO
CVE-2023-25164HIGH
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in
Feb 8, 20237.524NONO
CVE-2026-24125MEDIUM
Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelat
Mar 12, 20266.322NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
18%
73%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None9 (81.8%)
Unknown0 (0.0%)
Required2 (18.2%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None7 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ssw.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ssw — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ssw's Products

View all 1 CNAs →

Top CWEs