CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Statamic: Account takeover via OAuth email matching without email-verification check
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable
Statamic: CSV formula injection in form submission exports
Statamic: Server-Side Request Forgery via Glide (DNS rebinding)
Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors
Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction
Statamic: Server-Side Request Forgery via Glide
Statamic: Email enumeration via forgot password endpoint
Statamic: Unsafe method invocation via query value resolution allows data destruction
Statamic allows unauthorized content access through missing authorization in its revision controllers
Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential
Statamic's live preview token bypasses content protection for unrelated entries
Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag
Statamic's Markdown preview endpoint exposes sensitive user data
Statamic is missing authorization check on taxonomy term creation via fieldtype
Statamic has Stored XSS via SVG Sanitization Bypass
Statamic has a path traversal in file dictionary fieldtype
Statamic: privilege escalation via stored cross-site scripting
Showing 1 to 25 CVEs · page 1 (more available)