VYPR

CMS

by Statamic

Source repositories

CVEs (37)

  • CVE-2026-71435MedAug 6, 2026
    risk 0.33cvss 6.1epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification…

  • CVE-2018-19598MedDec 19, 2018
    risk 0.31cvss 4.8epss 0.01

    Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

  • CVE-2023-36828MedJul 5, 2023
    risk 0.29cvss 5.5epss 0.01

    Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the…

  • CVE-2026-45660MedMay 29, 2026
    risk 0.28cvss 5.4epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the…

  • CVE-2026-32612MedMar 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user…

  • CVE-2026-71434MedAug 6, 2026
    risk 0.27cvss 5.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could upload file types an administrator had…

  • CVE-2026-44306MedMay 12, 2026
    risk 0.27cvss 5.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could use this to enumerate valid users, which…

  • CVE-2024-52600MedNov 19, 2024
    risk 0.27cvss 5.3epss 0.01

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets`…

  • CVE-2026-64664MedAug 6, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having…

  • CVE-2026-33177MedMar 20, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileged Control Panel users could create taxonomy terms by submitting requests to the field action processing endpoint with attacker-controlled field definitions.…

  • CVE-2026-33171MedMar 20, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration…

  • CVE-2026-25633MedFeb 11, 2026
    risk 0.21cvss 4.3epss 0.00

    Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are…

  • CVE-2024-36119LowMay 30, 2024
    risk 0.05cvss 1.8epss 0.00

    Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the…

  • CVE-2026-54244LowJul 17, 2026
    risk 0.00cvss 3.5epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked view authorization, but it accepts and renders…

  • CVE-2026-54243MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value…

  • CVE-2026-54242MedJul 17, 2026
    risk 0.00cvss 4.9epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and src/Imaging/GuzzleAdapter.php could be bypassed using DNS rebinding. The remote hostname was…

  • CVE-2022-24784LowMar 25, 2022
    risk 0.00cvss 3.7epss 0.01

    Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually…

Page 2 of 2