Statamic

Statamic

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 19.11.2024 17:15:56
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects ...

  • EPSS 1.44%
  • Veröffentlicht 01.02.2024 17:15:11
  • Zuletzt bearbeitet 21.11.2024 08:59:26

Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, an...

  • EPSS 0.95%
  • Veröffentlicht 21.11.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:32:17

Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the ...

  • EPSS 1.05%
  • Veröffentlicht 14.11.2023 22:15:31
  • Zuletzt bearbeitet 21.11.2024 08:31:13

Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms u...

  • EPSS 4.86%
  • Veröffentlicht 10.11.2023 19:15:16
  • Zuletzt bearbeitet 21.11.2024 08:29:50

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms"...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 05.07.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 08:10:41

Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG...

  • EPSS 0.27%
  • Veröffentlicht 25.03.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:05

Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple su...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 10.02.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:32:08

A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in a...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 19.12.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:15

Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

  • EPSS 0.2%
  • Veröffentlicht 24.07.2017 12:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.