Statamic

Statamic

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 27.03.2026 20:41:23
  • Zuletzt bearbeitet 08.04.2026 13:54:27

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the req...

  • EPSS 0.04%
  • Veröffentlicht 27.03.2026 20:40:22
  • Zuletzt bearbeitet 08.04.2026 14:04:00

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration val...

  • EPSS 0.04%
  • Veröffentlicht 27.03.2026 20:39:17
  • Zuletzt bearbeitet 08.04.2026 14:07:18

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to ext...

  • EPSS 0.03%
  • Veröffentlicht 27.03.2026 20:38:19
  • Zuletzt bearbeitet 08.04.2026 14:17:43

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was...

  • EPSS 0.03%
  • Veröffentlicht 27.03.2026 20:37:21
  • Zuletzt bearbeitet 08.04.2026 14:23:30

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that execu...

  • EPSS 0.06%
  • Veröffentlicht 27.03.2026 20:36:31
  • Zuletzt bearbeitet 08.04.2026 14:27:34

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, ...

  • EPSS 0.01%
  • Veröffentlicht 20.03.2026 21:41:36
  • Zuletzt bearbeitet 23.03.2026 18:45:27

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileged Control Panel users could create taxonomy terms by submitting requests to the field action processing endpoint with attacker-co...

  • EPSS 0.01%
  • Veröffentlicht 20.03.2026 21:40:46
  • Zuletzt bearbeitet 23.03.2026 18:46:04

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inje...

  • EPSS 0.01%
  • Veröffentlicht 20.03.2026 21:39:40
  • Zuletzt bearbeitet 23.03.2026 18:46:31

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary'...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 12.03.2026 21:47:21
  • Zuletzt bearbeitet 19.03.2026 13:28:12

Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a high...