Security Advisories for tinacms in npm
High
3 months ago
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
npm
@tinacms/app, tinacms
Moderate
3 months ago
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
npm
@tinacms/mdx, tinacms
High
9 months ago
tinacms is vulnerable to arbitrary code execution
npm
@tinacms/graphql, @tinacms/cli, tinacms
Potential
Potential