CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-71435 MEDIUM

Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template

CVSS 6.1 EPSS 0.34% Aug 6, 2026
CVE-2026-71434 MEDIUM

Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types

CVSS 5.3 EPSS 0.41% Aug 6, 2026
CVE-2026-64662 MEDIUM

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

CVSS 6.5 EPSS 0.41% Aug 6, 2026
CVE-2026-64663 MEDIUM

Statamic: Unsafe method invocation via Antlers template resolution allows data destruction

CVSS 6.5 EPSS 0.40% Aug 6, 2026
CVE-2026-64665 HIGH

Statamic: Account takeover via OAuth email matching without email-verification check

CVSS 8.1 EPSS 0.54% Aug 6, 2026
CVE-2026-64664 MEDIUM

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

CVSS 4.3 EPSS 0.34% Aug 6, 2026
CVE-2026-71293 MEDIUM

Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable

CVSS 6.2 EPSS 0.37% Aug 5, 2026
CVE-2026-54243 MEDIUM

Statamic: CSV formula injection in form submission exports

CVSS 6.1 EPSS 0.34% Jul 17, 2026
CVE-2026-54242 MEDIUM

Statamic: Server-Side Request Forgery via Glide (DNS rebinding)

CVSS 4.9 EPSS 0.23% Jul 17, 2026
CVE-2026-54244 LOW

Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors

CVSS 3.5 EPSS 0.30% Jul 17, 2026
CVE-2026-49288 MEDIUM

Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

CVSS 4.3 EPSS 0.27% Jun 19, 2026
CVE-2026-49287 HIGH

Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction

CVSS 7.4 EPSS 0.46% Jun 19, 2026
CVE-2026-45660 MEDIUM

Statamic: Server-Side Request Forgery via Glide

CVSS 5.4 EPSS 0.24% May 29, 2026
CVE-2026-44306 MEDIUM

Statamic: Email enumeration via forgot password endpoint

CVSS 5.3 EPSS 0.34% May 12, 2026
CVE-2026-41175 HIGH

Statamic: Unsafe method invocation via query value resolution allows data destruction

CVSS 8.1 EPSS 0.56% Apr 22, 2026
CVE-2026-33887 MEDIUM

Statamic allows unauthorized content access through missing authorization in its revision controllers

CVSS 5.4 EPSS 0.24% Mar 27, 2026
CVE-2026-33886 MEDIUM

Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields

CVSS 6.5 EPSS 0.38% Mar 27, 2026
CVE-2026-33885 MEDIUM

Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential

CVSS 6.1 EPSS 0.30% Mar 27, 2026
CVE-2026-33884 MEDIUM

Statamic's live preview token bypasses content protection for unrelated entries

CVSS 4.3 EPSS 0.27% Mar 27, 2026
CVE-2026-33883 MEDIUM

Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag

CVSS 6.1 EPSS 0.25% Mar 27, 2026
CVE-2026-33882 MEDIUM

Statamic's Markdown preview endpoint exposes sensitive user data

CVSS 6.5 EPSS 0.44% Mar 27, 2026
CVE-2026-33177 MEDIUM

Statamic is missing authorization check on taxonomy term creation via fieldtype

CVSS 4.3 EPSS 0.27% Mar 20, 2026
CVE-2026-33172 HIGH

Statamic has Stored XSS via SVG Sanitization Bypass

CVSS 8.7 EPSS 0.36% Mar 20, 2026
CVE-2026-33171 MEDIUM

Statamic has a path traversal in file dictionary fieldtype

CVSS 4.3 EPSS 0.35% Mar 20, 2026
CVE-2026-32612 MEDIUM

Statamic: privilege escalation via stored cross-site scripting

CVSS 5.4 EPSS 0.25% Mar 12, 2026

Showing 1 to 25 CVEs · page 1 (more available)