ssw records
11 published records for vendor ssw.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-28792No exploit | Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMSssw · tinacms\/cli · CWE-22 | Critical9.6 | — | 0.6% | Mar 12, 2026 |
35Monitor | CVE-2026-34604No exploit | @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctionsssw · tinacms\/graphql · CWE-22 | High8.8 | — | 0.5% | Apr 1, 2026 |
33Monitor | CVE-2026-34603No exploit | @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctionsssw · tinacms\/cli · CWE-22 | High8.3 | — | 0.5% | Apr 1, 2026 |
33Monitor | CVE-2026-28793No exploit | Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMSssw · tinacms\/cli · CWE-22 | High8.4 | — | 0.2% | Mar 12, 2026 |
32Monitor | CVE-2026-33949No exploit | @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary filesssw · tinacms\/graphql · CWE-22 | High8.1 | — | 0.6% | Apr 1, 2026 |
30Monitor | CVE-2023-25164No exploit | Sensitive Information leak via Script File in TinaCMSssw · tinacms\/cli · CWE-200 | High7.5 | — | 0.7% | Feb 8, 2023 |
30Monitor | CVE-2024-45391No exploit | Tina search token leak via lock file in TinaCMSssw · tinacms\/cli · CWE-200 | High7.5 | — | 0.3% | Sep 3, 2024 |
29Monitor | CVE-2025-68278No exploit | tinacms vulnerable to arbitrary code executionssw · tinacms · CWE-94 | High7.3 | — | 0.5% | Dec 18, 2025 |
29Monitor | CVE-2026-28791No exploit | Path Traversal in Media Upload Handle in Tinassw · tinacms\/cli · CWE-22 | High7.4 | — | 0.4% | Mar 12, 2026 |
25Monitor | CVE-2026-24125No exploit | Path Traversal in @tinacms/graphqlssw · tinacms\/graphql · CWE-22 | Medium6.3 | — | 0.4% | Mar 12, 2026 |
24Monitor | CVE-2026-29066Proof of concept | Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLIssw · tinacms\/cli · CWE-200 | Medium6.2 | — | 0.6% | Mar 12, 2026 |
- CVE-2026-2879238Monitor
Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
CriticalCVSS 9.6No exploitEPSS 1%ssw · tinacms\/cliMar 12, 2026
- CVE-2026-3460435Monitor
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions
HighCVSS 8.8No exploitEPSS 1%ssw · tinacms\/graphqlApr 1, 2026
- CVE-2026-3460333Monitor
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions
HighCVSS 8.3No exploitEPSS 0%ssw · tinacms\/cliApr 1, 2026
- CVE-2026-2879333Monitor
Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS
HighCVSS 8.4No exploitEPSS 0%ssw · tinacms\/cliMar 12, 2026
- CVE-2026-3394932Monitor
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
HighCVSS 8.1No exploitEPSS 1%ssw · tinacms\/graphqlApr 1, 2026
- CVE-2023-2516430Monitor
Sensitive Information leak via Script File in TinaCMS
HighCVSS 7.5No exploitEPSS 1%ssw · tinacms\/cliFeb 8, 2023
- CVE-2024-4539130Monitor
Tina search token leak via lock file in TinaCMS
HighCVSS 7.5No exploitEPSS 0%ssw · tinacms\/cliSep 3, 2024
- CVE-2025-6827829Monitor
tinacms vulnerable to arbitrary code execution
HighCVSS 7.3No exploitEPSS 0%ssw · tinacmsDec 18, 2025
- CVE-2026-2879129Monitor
Path Traversal in Media Upload Handle in Tina
HighCVSS 7.4No exploitEPSS 0%ssw · tinacms\/cliMar 12, 2026
- CVE-2026-2412525Monitor
Path Traversal in @tinacms/graphql
MediumCVSS 6.3No exploitEPSS 0%ssw · tinacms\/graphqlMar 12, 2026
- CVE-2026-2906624Monitor
Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI
MediumCVSS 6.2Proof of conceptEPSS 1%ssw · tinacms\/cliMar 12, 2026