İçeriğe atla
Noroxi

statamic kayıtları

statamic üreticisine ait 30 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%93,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

30 kayıt
  • CVE-2021-45364
    40Planlayın

    A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php.

    KritikCVSS 9,8İstismar yokEPSS %2

    statamic · statamic10 Şub 2022

  • CVE-2023-47129
    39İzleyin

    Statamic CMS remote code execution via front-end form uploads

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    statamic · statamic10 Kas 2023

  • CVE-2023-48217
    35İzleyin

    Remote code execution via form uploads in statamic/cms

    YüksekCVSS 8,8İstismar yokEPSS %1

    statamic · statamic14 Kas 2023

  • CVE-2017-11422
    35İzleyin

    Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called.

    YüksekCVSS 8,8İstismar yokEPSS %1

    statamic · statamic24 Tem 2017

  • CVE-2026-27593
    35İzleyin

    Statamic is vulnerable to account takeover via password reset link injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    statamic · statamic24 Şub 2026

  • CVE-2026-27939
    35İzleyin

    Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass

    YüksekCVSS 8,8İstismar yokEPSS %0

    statamic · statamic27 Şub 2026

  • CVE-2026-28423
    34İzleyin

    Statamic Vulnerable to Server-Side Request Forgery via Glide

    YüksekCVSS 8,6İstismar yokEPSS %0

    statamic · statamic27 Şub 2026

  • CVE-2026-25759
    34İzleyin

    Statmatic affected by privilege escalation via stored cross-site scripting

    YüksekCVSS 8,7İstismar yokEPSS %0

    statamic · statamic11 Şub 2026

  • CVE-2026-33172
    34İzleyin

    Statamic has Stored XSS via SVG Sanitization Bypass

    YüksekCVSS 8,7İstismar yokEPSS %0

    statamic · statamic20 Mar 2026

  • CVE-2026-28425
    32İzleyin

    Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs

    YüksekCVSS 8,0İstismar yokEPSS %1

    statamic · statamic27 Şub 2026

  • CVE-2026-41175
    32İzleyin

    Statamic: Unsafe method invocation via query value resolution allows data destruction

    YüksekCVSS 8,1İstismar yokEPSS %1

    statamic · statamic22 Nis 2026

  • CVE-2026-33882
    26İzleyin

    Statamic's Markdown preview endpoint exposes sensitive user data

    OrtaCVSS 6,5İstismar yokEPSS %0

    statamic · statamic27 Mar 2026

  • CVE-2026-28424
    26İzleyin

    Statamic's missing authorization allows access to email addresses

    OrtaCVSS 6,5İstismar yokEPSS %0

    statamic · statamic27 Şub 2026

  • CVE-2026-33886
    26İzleyin

    Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields

    OrtaCVSS 6,5İstismar yokEPSS %0

    statamic · statamic27 Mar 2026

  • CVE-2024-24570
    24İzleyin

    Statamic account takeover via XSS and password reset link

    OrtaCVSS 6,1İstismar yokEPSS %1

    statamic · statamic1 Şub 2024

  • CVE-2023-48701
    24İzleyin

    Statamic CMS vulnerable to Cross-site Scripting via uploaded assets

    OrtaCVSS 6,1İstismar yokEPSS %1

    statamic · statamic21 Kas 2023

  • CVE-2026-33885
    24İzleyin

    Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential

    OrtaCVSS 6,1İstismar yokEPSS %0

    statamic · statamic27 Mar 2026

  • CVE-2026-33883
    24İzleyin

    Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag

    OrtaCVSS 6,1İstismar yokEPSS %0

    statamic · statamic27 Mar 2026

  • CVE-2023-36828
    21İzleyin

    Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG

    OrtaCVSS 5,4İstismar yokEPSS %1

    statamic · statamic5 Tem 2023

  • CVE-2024-52600
    21İzleyin

    Statamic CMS has Path Traversal in Asset Upload

    OrtaCVSS 5,3İstismar yokEPSS %1

    statamic · cms19 Kas 2024

  • CVE-2026-28426
    21İzleyin

    Statamic vulnerable to privilege escalation via stored cross-site scripting

    OrtaCVSS 5,4İstismar yokEPSS %0

    statamic · statamic27 Şub 2026

  • CVE-2026-32612
    21İzleyin

    Statamic: privilege escalation via stored cross-site scripting

    OrtaCVSS 5,4İstismar yokEPSS %0

    statamic · statamic13 Mar 2026

  • CVE-2026-33887
    21İzleyin

    Statamic allows unauthorized content access through missing authorization in its revision controllers

    OrtaCVSS 5,4İstismar yokEPSS %0

    statamic · statamic27 Mar 2026

  • CVE-2018-19598
    19İzleyin

    Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

    OrtaCVSS 4,8İstismar yokEPSS %1

    statamic · statamic19 Ara 2018

  • CVE-2026-27196
    19İzleyin

    Statamic affected by privilege escalation via stored Cross-site Scripting

    OrtaCVSS 4,8İstismar yokEPSS %0

    statamic · statamic21 Şub 2026