Skip to content

Known CVE

TinaCMS - Path Traversal

TinaCMS CLI < 2.1.8 contains a file system read vulnerability caused by disabled Vite server.fs.strict setting, letting unauthenticated attackers read arbitrary files on the host system, exploit requires access to the dev server.

CVE-2026-29066

Medium2026CVSS 6.2CWE-200

cve2026 · tinacms · lfi · vuln · unauthenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website