statamic records
30 published records for vendor statamic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 93.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-862 Missing Authorization4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-45364No exploit | A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php.statamic · statamic | Critical9.8 | — | 1.7% | Feb 10, 2022 |
39Monitor | CVE-2023-47129Proof of concept | Statamic CMS remote code execution via front-end form uploadsstatamic · statamic · CWE-434 | Critical9.8 | — | 1.1% | Nov 10, 2023 |
35Monitor | CVE-2023-48217No exploit | Remote code execution via form uploads in statamic/cmsstatamic · statamic · CWE-94 | High8.8 | — | 1.1% | Nov 14, 2023 |
35Monitor | CVE-2017-11422No exploit | Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called.statamic · statamic · CWE-732 | High8.8 | — | 0.9% | Jul 24, 2017 |
35Monitor | CVE-2026-27593No exploit | Statamic is vulnerable to account takeover via password reset link injectionstatamic · statamic · CWE-640 | High8.8 | — | 0.6% | Feb 24, 2026 |
35Monitor | CVE-2026-27939No exploit | Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypassstatamic · statamic · CWE-287 | High8.8 | — | 0.5% | Feb 27, 2026 |
34Monitor | CVE-2026-28423No exploit | Statamic Vulnerable to Server-Side Request Forgery via Glidestatamic · statamic · CWE-918 | High8.6 | — | 0.5% | Feb 27, 2026 |
34Monitor | CVE-2026-25759No exploit | Statmatic affected by privilege escalation via stored cross-site scriptingstatamic · statamic · CWE-79 | High8.7 | — | 0.4% | Feb 11, 2026 |
34Monitor | CVE-2026-33172No exploit | Statamic has Stored XSS via SVG Sanitization Bypassstatamic · statamic · CWE-79 | High8.7 | — | 0.4% | Mar 20, 2026 |
32Monitor | CVE-2026-28425No exploit | Statamic vulnerable to remote code execution via Antlers-enabled control panel inputsstatamic · statamic · CWE-94 | High8.0 | — | 0.8% | Feb 27, 2026 |
32Monitor | CVE-2026-41175No exploit | Statamic: Unsafe method invocation via query value resolution allows data destructionstatamic · statamic · CWE-470 | High8.1 | — | 0.6% | Apr 22, 2026 |
26Monitor | CVE-2026-33882No exploit | Statamic's Markdown preview endpoint exposes sensitive user datastatamic · statamic · CWE-20 | Medium6.5 | — | 0.4% | Mar 27, 2026 |
26Monitor | CVE-2026-28424No exploit | Statamic's missing authorization allows access to email addressesstatamic · statamic · CWE-862 | Medium6.5 | — | 0.4% | Feb 27, 2026 |
26Monitor | CVE-2026-33886No exploit | Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fieldsstatamic · statamic · CWE-200 | Medium6.5 | — | 0.4% | Mar 27, 2026 |
24Monitor | CVE-2024-24570No exploit | Statamic account takeover via XSS and password reset linkstatamic · statamic · CWE-79 | Medium6.1 | — | 0.7% | Feb 1, 2024 |
24Monitor | CVE-2023-48701No exploit | Statamic CMS vulnerable to Cross-site Scripting via uploaded assetsstatamic · statamic · CWE-79 | Medium6.1 | — | 0.7% | Nov 21, 2023 |
24Monitor | CVE-2026-33885No exploit | Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differentialstatamic · statamic · CWE-601 | Medium6.1 | — | 0.3% | Mar 27, 2026 |
24Monitor | CVE-2026-33883No exploit | Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tagstatamic · statamic · CWE-79 | Medium6.1 | — | 0.3% | Mar 27, 2026 |
21Monitor | CVE-2023-36828No exploit | Statamic's Antlers sanitizer cannot effectively sanitize malicious SVGstatamic · statamic · CWE-79 | Medium5.4 | — | 0.7% | Jul 5, 2023 |
21Monitor | CVE-2024-52600No exploit | Statamic CMS has Path Traversal in Asset Uploadstatamic · cms · CWE-22 | Medium5.3 | — | 0.6% | Nov 19, 2024 |
21Monitor | CVE-2026-28426No exploit | Statamic vulnerable to privilege escalation via stored cross-site scriptingstatamic · statamic · CWE-79 | Medium5.4 | — | 0.4% | Feb 27, 2026 |
21Monitor | CVE-2026-32612No exploit | Statamic: privilege escalation via stored cross-site scriptingstatamic · statamic · CWE-79 | Medium5.4 | — | 0.3% | Mar 13, 2026 |
21Monitor | CVE-2026-33887No exploit | Statamic allows unauthorized content access through missing authorization in its revision controllersstatamic · statamic · CWE-862 | Medium5.4 | — | 0.2% | Mar 27, 2026 |
19Monitor | CVE-2018-19598No exploit | Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.statamic · statamic · CWE-79 | Medium4.8 | — | 0.6% | Dec 19, 2018 |
19Monitor | CVE-2026-27196No exploit | Statamic affected by privilege escalation via stored Cross-site Scriptingstatamic · statamic · CWE-79 | Medium4.8 | — | 0.4% | Feb 21, 2026 |
- CVE-2021-4536440Plan
A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php.
CriticalCVSS 9.8No exploitEPSS 2%statamic · statamicFeb 10, 2022
- CVE-2023-4712939Monitor
Statamic CMS remote code execution via front-end form uploads
CriticalCVSS 9.8Proof of conceptEPSS 1%statamic · statamicNov 10, 2023
- CVE-2023-4821735Monitor
Remote code execution via form uploads in statamic/cms
HighCVSS 8.8No exploitEPSS 1%statamic · statamicNov 14, 2023
- CVE-2017-1142235Monitor
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called.
HighCVSS 8.8No exploitEPSS 1%statamic · statamicJul 24, 2017
- CVE-2026-2759335Monitor
Statamic is vulnerable to account takeover via password reset link injection
HighCVSS 8.8No exploitEPSS 1%statamic · statamicFeb 24, 2026
- CVE-2026-2793935Monitor
Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
HighCVSS 8.8No exploitEPSS 0%statamic · statamicFeb 27, 2026
- CVE-2026-2842334Monitor
Statamic Vulnerable to Server-Side Request Forgery via Glide
HighCVSS 8.6No exploitEPSS 0%statamic · statamicFeb 27, 2026
- CVE-2026-2575934Monitor
Statmatic affected by privilege escalation via stored cross-site scripting
HighCVSS 8.7No exploitEPSS 0%statamic · statamicFeb 11, 2026
- CVE-2026-3317234Monitor
Statamic has Stored XSS via SVG Sanitization Bypass
HighCVSS 8.7No exploitEPSS 0%statamic · statamicMar 20, 2026
- CVE-2026-2842532Monitor
Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs
HighCVSS 8.0No exploitEPSS 1%statamic · statamicFeb 27, 2026
- CVE-2026-4117532Monitor
Statamic: Unsafe method invocation via query value resolution allows data destruction
HighCVSS 8.1No exploitEPSS 1%statamic · statamicApr 22, 2026
- CVE-2026-3388226Monitor
Statamic's Markdown preview endpoint exposes sensitive user data
MediumCVSS 6.5No exploitEPSS 0%statamic · statamicMar 27, 2026
- CVE-2026-2842426Monitor
Statamic's missing authorization allows access to email addresses
MediumCVSS 6.5No exploitEPSS 0%statamic · statamicFeb 27, 2026
- CVE-2026-3388626Monitor
Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
MediumCVSS 6.5No exploitEPSS 0%statamic · statamicMar 27, 2026
- CVE-2024-2457024Monitor
Statamic account takeover via XSS and password reset link
MediumCVSS 6.1No exploitEPSS 1%statamic · statamicFeb 1, 2024
- CVE-2023-4870124Monitor
Statamic CMS vulnerable to Cross-site Scripting via uploaded assets
MediumCVSS 6.1No exploitEPSS 1%statamic · statamicNov 21, 2023
- CVE-2026-3388524Monitor
Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential
MediumCVSS 6.1No exploitEPSS 0%statamic · statamicMar 27, 2026
- CVE-2026-3388324Monitor
Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag
MediumCVSS 6.1No exploitEPSS 0%statamic · statamicMar 27, 2026
- CVE-2023-3682821Monitor
Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG
MediumCVSS 5.4No exploitEPSS 1%statamic · statamicJul 5, 2023
- CVE-2024-5260021Monitor
Statamic CMS has Path Traversal in Asset Upload
MediumCVSS 5.3No exploitEPSS 1%statamic · cmsNov 19, 2024
- CVE-2026-2842621Monitor
Statamic vulnerable to privilege escalation via stored cross-site scripting
MediumCVSS 5.4No exploitEPSS 0%statamic · statamicFeb 27, 2026
- CVE-2026-3261221Monitor
Statamic: privilege escalation via stored cross-site scripting
MediumCVSS 5.4No exploitEPSS 0%statamic · statamicMar 13, 2026
- CVE-2026-3388721Monitor
Statamic allows unauthorized content access through missing authorization in its revision controllers
MediumCVSS 5.4No exploitEPSS 0%statamic · statamicMar 27, 2026
- CVE-2018-1959819Monitor
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
MediumCVSS 4.8No exploitEPSS 1%statamic · statamicDec 19, 2018
- CVE-2026-2719619Monitor
Statamic affected by privilege escalation via stored Cross-site Scripting
MediumCVSS 4.8No exploitEPSS 0%statamic · statamicFeb 21, 2026