CPE
The @tinacms/web-components package is vulnerable to stored Cross-Site Scripting (XSS) due to a failure to validate URL schemes in the tina-markdown component, allowing attackers to execute arbitrary code in the browser context of site visitors.