Known CVE
TinaCMS - Path Traversal
TinaCMS CLI < 2.1.8 contains a file system read vulnerability caused by disabled Vite server.fs.strict setting, letting unauthenticated attackers read arbitrary files on the host system, exploit requires access to the dev server.
CVE-2026-29066
Medium2026CVSS 6.2CWE-200
cve2026 · tinacms · lfi · vuln · unauthenticated
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website