Tina4 is a niche web application framework and stack product that presents a focused vulnerability footprint centered on application-layer input-handling and request-validation weaknesses. Observed disclosures cluster around cross-site request forgery and SQL injection, which are characteristic of web application development platforms and reflect the input-sanitization and state-validation demands on framework implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tina4 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25187CRITICAL Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly | Mar 6, 2026 | 9.8 | 31 | NO | NO |
CVE-2018-25186MEDIUM Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpo | Mar 6, 2026 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tina4.
Media articles that mention a CVE ID that affects a product developed by Tina4 — matched by CVE ID, not by vendor name.