Statamic/cms
This hub aggregates every CVE we track for Statamic/cms, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
20
CVEs tracked
1
Critical
11
High
0
In CISA KEV
Severity distribution
HIGH11MEDIUM6LOW2CRITICAL1
Monthly trend
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
1
0
0
0
9
1
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Statamic/cms.
- CVE-2026-32612Statamic: privilege escalation via stored cross-site scripting5.4
- CVE-2026-28426Statamic vulnerable to privilege escalation via stored cross-site scripting8.7
- CVE-2026-28425Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs8.0
- CVE-2026-28424Statamic's missing authorization allows access to email addresses6.5
- CVE-2026-28423Statamic Vulnerable to Server-Side Request Forgery via Glide6.8
- CVE-2026-27939Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass8.8
- CVE-2026-27593Statamic is vulnerable to account takeover via password reset link injection9.3
- CVE-2026-27196Statamic affected by privilege escalation via stored Cross-site Scripting8.1
- CVE-2026-25759Statmatic affected by privilege escalation via stored cross-site scripting8.7
- CVE-2026-25633Statamic's missing authorization allows access to assets4.3
- CVE-2025-64112Statmatic vulnerable to Stored Cross-Site Scripting8.0
- CVE-2024-52600Statamic CMS has Path Traversal in Asset Upload5.3
- CVE-2024-36119Password confirmation stored in plain text via registration form in statamic/cms1.8
- CVE-2024-24570Statamic account takeover via XSS and password reset link8.2
- CVE-2023-48701Statamic CMS vulnerable to Cross-site Scripting via uploaded assets7.5
Product normalization is registry-driven with AI assist and human review. How it works