← Back to the live CVE advisory feed

CVE-2026-108260: Product identification pending

Severity
7.6 (HIGH)
Affected versions
Before 0.2.1
Fixed version
0.2.1.
Patch status
Patched
Published
2026-10-09T21:17:04.180
Modified
2026-10-09T21:17:04.180

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A content author can store a link using a script-capable scheme, and a visitor who clicks the rendered link executes attacker-controlled script in the site's origin. The script can access same-origin application data and, when the visitor is an editor or administrator, may expose credentials stored by the TinaCMS admin on that origin. This issue is fixed in version 0.2.1.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 10, 2026 04:00 PM UTC
275 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-108263
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-108474
Product identification pending PATCH
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-104732
Advanced IP Blocker
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94589
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-103889
3D Product configurator for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-104803
WPCOM Member
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-62045
Booklovers
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-62046
Gutentype
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93927
Veto
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93929
Travesia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93930
Tantra
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93931
Smash
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93932
Smart Casa
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93933
Rosalinda
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93934
Partiso
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93935
Let's Play
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93936
IPharm
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93937
Hygia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93938
Hogwords
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93940
Greeny
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93941
Edema
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93942
Dwell
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93943
Convex
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93944
Camelia
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-93945
Balance
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-107824
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-107845
contao PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-108261
tinacms PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-108551
openapi-typescript-codegen
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-108157
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-108549
Product identification pending
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-108264
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108265
enclave-os-mini PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108266
rustls PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108267
go PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108268
enclave-os-virtual PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-108269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-107645
Blocksy Companion
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-97670
Avada (Fusion) Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-104801
PPOM – Product Addons & Custom Fields for WooCommerce
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-107807
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107809
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107811
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107813
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55797
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-104723
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104725
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-104766
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-77183
FooSales – Point of Sale (POS) for WooCommerce
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-83526
FV Player 8
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-87780
Product identification pending PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-105885
Product identification pending
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-104084
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108113
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-108550
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-104082
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-87781
Product identification pending PATCH
Reporter: CONTACT
8.6
HIGH
VIEW RECORD
CVE-2026-107815
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-107814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-107818
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-101947
Product identification pending
Reporter: HELP
8.4
HIGH
VIEW RECORD
CVE-2026-102554
Product identification pending
Reporter: CVE-COORDINATION
8.2
HIGH
VIEW RECORD
CVE-2026-90983
Product identification pending PATCH
Reporter: ILETISIM
8.2
HIGH
VIEW RECORD
CVE-2026-107837
Product identification pending
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-108259
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-22061
Product identification pending
Reporter: SECURITY-ALERT
8.2
HIGH
VIEW RECORD
CVE-2026-108545
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-107808
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-107810
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-57458
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62376
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-104797
Advanced Form Integration — Connect Forms to 300+ Apps
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104899
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-92975
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-94256
Product identification pending PATCH
Reporter: CONTACT
8.1
HIGH
VIEW RECORD
CVE-2026-94257
Product identification pending PATCH
Reporter: CONTACT
8.1
HIGH
VIEW RECORD
CVE-2026-94538
WP File Download
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-104759
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-107821
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8
HIGH
VIEW RECORD
CVE-2026-92705
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-108159
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108160
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108161
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108546
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108553
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-108110
Product identification pending
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-108260
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-107812
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-75345
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75346
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75348
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75349
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75347
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-107826
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-107838
Product identification pending
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-107839
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-107840
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-75350
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-75351
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-62367
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.