pkg:npm/tinacms
4 total CVEsHIGH1
✅ Check your installed version
All known vulnerabilities
from 0, < 2.1.7
—CVE-2026-55660TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover from 0, < 3.9.3
—CVE-2026-55661TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes from 0, < 3.9.3
from 0, < 3.1.1