Skip to content
Noroxi

ssw records

11 published records for vendor ssw.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

    CriticalCVSS 9.6No exploitEPSS 1%

    ssw · tinacms\/cliMar 12, 2026

  • @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions

    HighCVSS 8.8No exploitEPSS 1%

    ssw · tinacms\/graphqlApr 1, 2026

  • @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions

    HighCVSS 8.3No exploitEPSS 0%

    ssw · tinacms\/cliApr 1, 2026

  • Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS

    HighCVSS 8.4No exploitEPSS 0%

    ssw · tinacms\/cliMar 12, 2026

  • @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

    HighCVSS 8.1No exploitEPSS 1%

    ssw · tinacms\/graphqlApr 1, 2026

  • Sensitive Information leak via Script File in TinaCMS

    HighCVSS 7.5No exploitEPSS 1%

    ssw · tinacms\/cliFeb 8, 2023

  • Tina search token leak via lock file in TinaCMS

    HighCVSS 7.5No exploitEPSS 0%

    ssw · tinacms\/cliSep 3, 2024

  • tinacms vulnerable to arbitrary code execution

    HighCVSS 7.3No exploitEPSS 0%

    ssw · tinacmsDec 18, 2025

  • Path Traversal in Media Upload Handle in Tina

    HighCVSS 7.4No exploitEPSS 0%

    ssw · tinacms\/cliMar 12, 2026

  • Path Traversal in @tinacms/graphql

    MediumCVSS 6.3No exploitEPSS 0%

    ssw · tinacms\/graphqlMar 12, 2026

  • Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI

    MediumCVSS 6.2Proof of conceptEPSS 1%

    ssw · tinacms\/cliMar 12, 2026