statamic
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting statamic.
- CVE-2026-71435Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template6.1
- CVE-2026-71434Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types5.3
- CVE-2026-64662Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries6.5
- CVE-2026-64663Statamic: Unsafe method invocation via Antlers template resolution allows data destruction6.5
- CVE-2026-64665Statamic: Account takeover via OAuth email matching without email-verification check8.1
- CVE-2026-64664Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence4.3
- CVE-2026-71293Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable6.2
- CVE-2026-54243Statamic: CSV formula injection in form submission exports6.1
- CVE-2026-54242Statamic: Server-Side Request Forgery via Glide (DNS rebinding)4.9
- CVE-2026-54244Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors3.5
- CVE-2026-49288Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources4.3
- CVE-2026-49287Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction7.4
- CVE-2026-45660Statamic: Server-Side Request Forgery via Glide5.4
- CVE-2026-44306Statamic: Email enumeration via forgot password endpoint5.3
- CVE-2026-41175Statamic: Unsafe method invocation via query value resolution allows data destruction8.1