Statamic

Statamic

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 24.02.2026 21:38:17
  • Zuletzt bearbeitet 25.02.2026 20:27:52

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The ...

  • EPSS 0.01%
  • Veröffentlicht 11.02.2026 20:37:37
  • Zuletzt bearbeitet 18.02.2026 19:37:29

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes...

  • EPSS 0.01%
  • Veröffentlicht 11.02.2026 20:33:51
  • Zuletzt bearbeitet 18.02.2026 19:36:44

Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to a...

  • EPSS 0.03%
  • Veröffentlicht 08.08.2025 00:00:00
  • Zuletzt bearbeitet 08.08.2025 20:30:18

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /user...

  • EPSS 0.39%
  • Veröffentlicht 19.11.2024 17:15:56
  • Zuletzt bearbeitet 19.11.2024 21:56:45

Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects ...

  • EPSS 1.39%
  • Veröffentlicht 01.02.2024 17:15:11
  • Zuletzt bearbeitet 21.11.2024 08:59:26

Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, an...

  • EPSS 0.95%
  • Veröffentlicht 21.11.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:32:17

Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the ...

  • EPSS 1.05%
  • Veröffentlicht 14.11.2023 22:15:31
  • Zuletzt bearbeitet 21.11.2024 08:31:13

Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms u...

  • EPSS 4.86%
  • Veröffentlicht 10.11.2023 19:15:16
  • Zuletzt bearbeitet 21.11.2024 08:29:50

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms"...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 05.07.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 08:10:41

Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG...