Statamic

Statamic

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 27.02.2026 22:23:42
  • Zuletzt bearbeitet 05.03.2026 14:32:00

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaSc...

  • EPSS 0.16%
  • Veröffentlicht 27.02.2026 22:20:39
  • Zuletzt bearbeitet 25.03.2026 21:16:39

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application con...

  • EPSS 0.04%
  • Veröffentlicht 27.02.2026 22:14:01
  • Zuletzt bearbeitet 05.03.2026 14:46:10

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view us...

  • EPSS 0.06%
  • Veröffentlicht 27.02.2026 22:11:55
  • Zuletzt bearbeitet 05.03.2026 14:47:10

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user t...

  • EPSS 0.02%
  • Veröffentlicht 27.02.2026 21:34:39
  • Zuletzt bearbeitet 10.03.2026 15:20:19

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended ve...

  • EPSS 0.02%
  • Veröffentlicht 24.02.2026 21:38:17
  • Zuletzt bearbeitet 25.02.2026 20:27:52

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The ...

  • EPSS 0.01%
  • Veröffentlicht 21.02.2026 04:30:05
  • Zuletzt bearbeitet 30.03.2026 15:22:05

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management per...

  • EPSS 0.01%
  • Veröffentlicht 11.02.2026 20:37:37
  • Zuletzt bearbeitet 18.02.2026 19:37:29

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes...

  • EPSS 0.01%
  • Veröffentlicht 11.02.2026 20:33:51
  • Zuletzt bearbeitet 18.02.2026 19:36:44

Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to a...

  • EPSS 0.03%
  • Veröffentlicht 08.08.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /user...