Statamic / Cms
43 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-71435 | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template | MEDIUM | 6.1 | Aug 6, 2026 |
| CVE-2026-71434 | Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types | MEDIUM | 5.3 | Aug 6, 2026 |
| CVE-2026-64662 | Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries | MEDIUM | 6.5 | Aug 6, 2026 |
| CVE-2026-64663 | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction | MEDIUM | 6.5 | Aug 6, 2026 |
| CVE-2026-64665 | Statamic: Account takeover via OAuth email matching without email-verification check | HIGH | 8.1 | Aug 6, 2026 |
| CVE-2026-64664 | Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence | MEDIUM | 4.3 | Aug 6, 2026 |
| CVE-2026-71293 | Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable | MEDIUM | 6.2 | Aug 5, 2026 |
| CVE-2026-54243 | Statamic: CSV formula injection in form submission exports | MEDIUM | 6.1 | Jul 17, 2026 |
| CVE-2026-54242 | Statamic: Server-Side Request Forgery via Glide (DNS rebinding) | MEDIUM | 4.9 | Jul 17, 2026 |
| CVE-2026-54244 | Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors | LOW | 3.5 | Jul 17, 2026 |
| CVE-2026-49288 | Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources | MEDIUM | 4.3 | Jun 19, 2026 |
| CVE-2026-49287 | Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction | HIGH | 7.4 | Jun 19, 2026 |
| CVE-2026-45660 | Statamic: Server-Side Request Forgery via Glide | MEDIUM | 5.4 | May 29, 2026 |
| CVE-2026-44306 | Statamic: Email enumeration via forgot password endpoint | MEDIUM | 5.3 | May 12, 2026 |
| CVE-2026-41175 | Statamic: Unsafe method invocation via query value resolution allows data destruction | HIGH | 8.1 | Apr 22, 2026 |
| CVE-2026-33887 | Statamic allows unauthorized content access through missing authorization in its revision controllers | MEDIUM | 5.4 | Mar 27, 2026 |
| CVE-2026-33886 | Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields | MEDIUM | 6.5 | Mar 27, 2026 |
| CVE-2026-33885 | Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential | MEDIUM | 6.1 | Mar 27, 2026 |
| CVE-2026-33884 | Statamic's live preview token bypasses content protection for unrelated entries | MEDIUM | 4.3 | Mar 27, 2026 |
| CVE-2026-33883 | Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag | MEDIUM | 6.1 | Mar 27, 2026 |
| CVE-2026-33882 | Statamic's Markdown preview endpoint exposes sensitive user data | MEDIUM | 6.5 | Mar 27, 2026 |
| CVE-2026-33177 | Statamic is missing authorization check on taxonomy term creation via fieldtype | MEDIUM | 4.3 | Mar 20, 2026 |
| CVE-2026-33172 | Statamic has Stored XSS via SVG Sanitization Bypass | HIGH | 8.7 | Mar 20, 2026 |
| CVE-2026-33171 | Statamic has a path traversal in file dictionary fieldtype | MEDIUM | 4.3 | Mar 20, 2026 |
| CVE-2026-32612 | Statamic: privilege escalation via stored cross-site scripting | MEDIUM | 5.4 | Mar 12, 2026 |
Showing 1 to 25 of 43 CVEs