CVEs we hold for Statamic
Records whose assigning authority named Statamic as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-71435Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Templatestatamic cms
CVE-2026-71434Statamic: Missing file upload validation on frontend forms allows uploading disallowed file typesstatamic cms
CVE-2026-71293Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variablestatamic cms
CVE-2026-64665Statamic: Account takeover via OAuth email matching without email-verification checkstatamic cms
CVE-2026-64664Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existencestatamic cms
CVE-2026-64663Statamic: Unsafe method invocation via Antlers template resolution allows data destructionstatamic cms
CVE-2026-64662Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entriesstatamic cms
CVE-2026-54244Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editorsstatamic cms
CVE-2026-49288Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resourcesstatamic cms
CVE-2026-49287Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destructionstatamic cms
CVE-2026-41175Statamic: Unsafe method invocation via query value resolution allows data destructionstatamic cms
CVE-2026-33887Statamic allows unauthorized content access through missing authorization in its revision controllersstatamic cms
CVE-2026-33886Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fieldsstatamic cms
CVE-2026-33885Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differentialstatamic cms
CVE-2026-33884Statamic's live preview token bypasses content protection for unrelated entriesstatamic cms
CVE-2026-33883Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tagstatamic cms
CVE-2026-33177Statamic is missing authorization check on taxonomy term creation via fieldtypestatamic cms
CVE-2026-28426Statamic vulnerable to privilege escalation via stored cross-site scriptingstatamic cms
CVE-2026-28425Statamic vulnerable to remote code execution via Antlers-enabled control panel inputsstatamic cms
CVE-2026-27939Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypassstatamic cms
CVE-2026-27593Statamic is vulnerable to account takeover via password reset link injectionstatamic cms
CVE-2026-25759Statmatic affected by privilege escalation via stored cross-site scriptingstatamic cms
CVE-2024-36119Password confirmation stored in plain text via registration form in statamic/cmsstatamic cms
43 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.