📦 Statamic

by Statamic

🔍 What is Statamic?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-27593

CRITICAL CVSS 9.3 Feb 24, 2026

This vulnerability in Statmatic CMS allows attackers to hijack password reset tokens and take over user accounts. Attackers need a valid email address and must trick users into clicking malicious rese...

CVE-2021-45364

CRITICAL CVSS 9.8 Feb 10, 2022

This CVE describes a code execution vulnerability in Statamic CMS versions through 3.2.26 via SettingsController.php. However, the vendor indicates this CVE was published in error and the affected cod...

CVE-2026-25759

HIGH CVSS 8.7 Feb 11, 2026

A stored cross-site scripting (XSS) vulnerability in Statmatic CMS allows authenticated users with content creation permissions to inject malicious JavaScript into content titles. When higher-privileg...

CVE-2023-48701

HIGH CVSS 7.5 Nov 21, 2023

This vulnerability allows attackers to upload HTML files disguised as images in Statamic CMS, bypassing MIME type validation. This affects front-end forms with asset fields and authenticated control p...

CVE-2023-48217

HIGH CVSS 8.8 Nov 14, 2023

This vulnerability allows attackers to upload malicious PHP files disguised as images through Statamic's front-end forms and control panel asset uploads, bypassing MIME type validation. Successful exp...

CVE-2023-47129

HIGH CVSS 8.3 Nov 10, 2023

This vulnerability allows attackers to upload malicious PHP files disguised as images through front-end forms in Statamic CMS. It affects websites using Statamic's Forms feature with asset upload fiel...