pkg:Packagist/statamic/cms
32 total CVEsCRITICAL1HIGH13MEDIUM16LOW2
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.3CVE-2026-27593Statamic is vulnerable to account takeover via password reset link injectionfrom 0, < 5.73.10
- HIGH8.8CVE-2026-27939Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass>= 6.0.0, < 6.4.0
- >= 4.0.0, < 4.34.0
- from 0, < 2.6.0
- >= 6.0.0-alpha.1, < 6.7.0
- from 0, < 5.73.11
- HIGH8.7CVE-2026-25759Statamic CMS vulnerable to privilege escalation via stored cross-site scripting>= 6.0.0, < 6.2.3
- >= 4.0.0, < 4.33.0
- >= 4.00, < 4.46.0
- HIGH8.1CVE-2026-41175Statamic: Unsafe method invocation via query value resolution allows data destructionfrom 0, < 5.73.20
- >= 6.0.0-alpha.1, < 6.3.2
- HIGH8.0CVE-2026-28425Statamic vulnerable to remote code execution via Antlers-enabled control panel inputsfrom 0, < 5.73.16
- HIGH8.0CVE-2025-64112Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validationfrom 0, < 5.22.1
- from 0, < 3.4.15
- from 0, < 5.73.11
- MEDIUM6.5CVE-2026-33886Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields>= 5.73.12, < 5.73.16
- from 0, < 5.73.16
- from 0, < 5.73.11
- MEDIUM6.1CVE-2026-33885Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differentialfrom 0, < 5.73.16
- MEDIUM6.1CVE-2026-33883Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tagfrom 0, < 5.73.16
- from 0, < 4.10.0
- from 0, < 5.73.22
- MEDIUM5.4CVE-2026-33887Statamic allows unauthorized content access through missing authorization in its revision controllersfrom 0, < 5.73.16
- >= 6.0.0, < 6.6.2
- from 0, < 5.73.21
- from 0, < 5.17.0
- MEDIUM4.3CVE-2026-33884Statamic's live preview token bypasses content protection for unrelated entriesfrom 0, < 5.73.16
- MEDIUM4.3CVE-2026-33177Statamic is missing authorization check on taxonomy term creation via fieldtype>= 6.0.0-alpha.1, < 6.7.0
- >= 6.0.0-alpha.1, < 6.7.0
- from 0, < 5.73.6
- from 0, < 3.2.39
- LOW1.8CVE-2024-36119Password confirmation stored in plain text via registration form in statamic/cms>= 5.3.0, < 5.6.2