Vulnerabilities in statamic
43 resultsVexday analysis
Statamic acumula 36 vulnerabilidades catalogadas, com 1 crítica, sendo a injeção de código (CWE-79) a fraqueza estrutural dominante. Embora nenhuma vulnerabilidade esteja sob exploração ativa, 7 foram publicadas nos últimos 90 dias, evidenciando ciclo de descoberta contínuo que demanda acompanhamento regular de patches.
CVE-2026-25633MEDIUMStatamic's missing authorization allows access to assetsEPSS 0.3%CVE-2026-27196HIGHStatamic affected by privilege escalation via stored Cross-site ScriptingEPSS 0.3%CVE-2026-49288MEDIUMStatamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resourcesEPSS 0.3%CVE-2026-28426HIGHStatamic vulnerable to privilege escalation via stored cross-site scriptingEPSS 0.3%CVE-2026-33882MEDIUMStatamic's Markdown preview endpoint exposes sensitive user dataEPSS 0.3%CVE-2026-64664MEDIUMStatamic: Missing authorization on Control Panel endpoint allows disclosure of user existenceEPSS 0.3%CVE-2026-71434MEDIUMStatamic: Missing file upload validation on frontend forms allows uploading disallowed file typesEPSS 0.2%CVE-2026-28424MEDIUMStatamic's missing authorization allows access to email addressesEPSS 0.2%CVE-2026-32612MEDIUMStatamic: privilege escalation via stored cross-site scriptingEPSS 0.2%CVE-2026-71293MEDIUMStatamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user VariableEPSS 0.2%CVE-2026-33177MEDIUMStatamic is missing authorization check on taxonomy term creation via fieldtypeEPSS 0.2%CVE-2026-33886MEDIUMStatamic's sensitive configuration values are exposed to content editors via Antlers-enabled fieldsEPSS 0.2%CVE-2026-44306MEDIUMStatamic: Email enumeration via forgot password endpointEPSS 0.2%CVE-2026-71435MEDIUMStatamic: Stored Cross-Site Scripting in Automagic Form Notification Email TemplateEPSS 0.2%CVE-2026-54243MEDIUMStatamic: CSV formula injection in form submission exportsEPSS 0.2%CVE-2026-33885MEDIUMStatamic has an Open Redirect on unauthenticated endpoints via URL parsing differentialEPSS 0.2%CVE-2026-54244LOWStatamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editorsEPSS 0.2%CVE-2026-33884MEDIUMStatamic's live preview token bypasses content protection for unrelated entriesEPSS 0.2%CVE-2026-45660MEDIUMStatamic: Server-Side Request Forgery via GlideEPSS 0.2%CVE-2026-33883MEDIUMStatamic has Reflected XSS via unescaped redirect parameter in its password reset form tagEPSS 0.1%