Skip to content
Noroxi

statamic records

30 published records for vendor statamic.

All records

30 records
  • A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    statamic · statamicFeb 10, 2022

  • Statamic CMS remote code execution via front-end form uploads

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    statamic · statamicNov 10, 2023

  • Remote code execution via form uploads in statamic/cms

    HighCVSS 8.8No exploitEPSS 1%

    statamic · statamicNov 14, 2023

  • Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called.

    HighCVSS 8.8No exploitEPSS 1%

    statamic · statamicJul 24, 2017

  • Statamic is vulnerable to account takeover via password reset link injection

    HighCVSS 8.8No exploitEPSS 1%

    statamic · statamicFeb 24, 2026

  • Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass

    HighCVSS 8.8No exploitEPSS 0%

    statamic · statamicFeb 27, 2026

  • Statamic Vulnerable to Server-Side Request Forgery via Glide

    HighCVSS 8.6No exploitEPSS 0%

    statamic · statamicFeb 27, 2026

  • Statmatic affected by privilege escalation via stored cross-site scripting

    HighCVSS 8.7No exploitEPSS 0%

    statamic · statamicFeb 11, 2026

  • Statamic has Stored XSS via SVG Sanitization Bypass

    HighCVSS 8.7No exploitEPSS 0%

    statamic · statamicMar 20, 2026

  • Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs

    HighCVSS 8.0No exploitEPSS 1%

    statamic · statamicFeb 27, 2026

  • Statamic: Unsafe method invocation via query value resolution allows data destruction

    HighCVSS 8.1No exploitEPSS 1%

    statamic · statamicApr 22, 2026

  • Statamic's Markdown preview endpoint exposes sensitive user data

    MediumCVSS 6.5No exploitEPSS 0%

    statamic · statamicMar 27, 2026

  • Statamic's missing authorization allows access to email addresses

    MediumCVSS 6.5No exploitEPSS 0%

    statamic · statamicFeb 27, 2026

  • Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields

    MediumCVSS 6.5No exploitEPSS 0%

    statamic · statamicMar 27, 2026

  • Statamic account takeover via XSS and password reset link

    MediumCVSS 6.1No exploitEPSS 1%

    statamic · statamicFeb 1, 2024

  • Statamic CMS vulnerable to Cross-site Scripting via uploaded assets

    MediumCVSS 6.1No exploitEPSS 1%

    statamic · statamicNov 21, 2023

  • Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential

    MediumCVSS 6.1No exploitEPSS 0%

    statamic · statamicMar 27, 2026

  • Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag

    MediumCVSS 6.1No exploitEPSS 0%

    statamic · statamicMar 27, 2026

  • Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG

    MediumCVSS 5.4No exploitEPSS 1%

    statamic · statamicJul 5, 2023

  • Statamic CMS has Path Traversal in Asset Upload

    MediumCVSS 5.3No exploitEPSS 1%

    statamic · cmsNov 19, 2024

  • Statamic vulnerable to privilege escalation via stored cross-site scripting

    MediumCVSS 5.4No exploitEPSS 0%

    statamic · statamicFeb 27, 2026

  • Statamic: privilege escalation via stored cross-site scripting

    MediumCVSS 5.4No exploitEPSS 0%

    statamic · statamicMar 13, 2026

  • Statamic allows unauthorized content access through missing authorization in its revision controllers

    MediumCVSS 5.4No exploitEPSS 0%

    statamic · statamicMar 27, 2026

  • Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

    MediumCVSS 4.8No exploitEPSS 1%

    statamic · statamicDec 19, 2018

  • Statamic affected by privilege escalation via stored Cross-site Scripting

    MediumCVSS 4.8No exploitEPSS 0%

    statamic · statamicFeb 21, 2026