VYPR
Vendor

Statamic

Products
2
CVEs
47
Across products
70
Status
Private

Products

2

Recent CVEs

47
View all 47 CVEs →
  • CVE-2021-45364CriFeb 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product

  • CVE-2020-9322HigAug 8, 2025
    risk 0.57cvss 8.8epss 0.00

    The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.

  • CVE-2017-11422HigJul 24, 2017
    risk 0.57cvss 8.8epss 0.01

    Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.

  • CVE-2026-27593CriFeb 24, 2026
    risk 0.53cvss 9.3epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email…

  • CVE-2026-33172HigMar 20, 2026
    risk 0.50cvss 8.7epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that…

  • CVE-2026-28426HigFeb 27, 2026
    risk 0.50cvss 8.7epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when…

  • CVE-2026-27939HigFeb 27, 2026
    risk 0.50cvss 8.8epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can…

  • CVE-2026-25759HigFeb 11, 2026
    risk 0.50cvss 8.7epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by…

  • CVE-2023-48217HigNov 14, 2023
    risk 0.50cvss 8.8epss 0.01

    Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and…

  • CVE-2023-47129HigNov 10, 2023
    risk 0.47cvss 8.3epss 0.01

    Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_…

  • CVE-2026-64665HigAug 6, 2026
    risk 0.46cvss 8.1epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including…

  • CVE-2026-41175HigApr 22, 2026
    risk 0.46cvss 8.1epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts.…

  • CVE-2026-27196HigFeb 21, 2026
    risk 0.46cvss 8.1epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious…

  • CVE-2024-24570HigFeb 1, 2024
    risk 0.46cvss 8.2epss 0.01

    Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the…

  • CVE-2026-28425HigFeb 27, 2026
    risk 0.45cvss 8.0epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full…

  • CVE-2025-64112HigOct 30, 2025
    risk 0.45cvss 8.0epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This…

  • CVE-2023-48701HigNov 21, 2023
    risk 0.42cvss 7.5epss 0.01

    Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an…

  • CVE-2026-49287HigJun 19, 2026
    risk 0.41cvss 7.4epss 0.00

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue in the query builder, but the same protection was not applied to in-memory collection sorting. Manipulating sort…

  • CVE-2026-71293MedAug 5, 2026
    risk 0.40cvss 6.2epss 0.00

    Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns the user's raw two-factor recovery codes with no access restriction.

  • CVE-2026-28423MedFeb 27, 2026
    risk 0.37cvss 6.8epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP…