Security Advisories for statamic/cms in packagist
Moderate
26 days ago
Statamic CMS vulnerable to email enumeration via forgot password endpoint
packagist
statamic/cms
High
about 2 months ago
Statamic: Unsafe method invocation via query value resolution allows data destruction
packagist
statamic/cms
Moderate
2 months ago
Statamic allows unauthorized content access through missing authorization in its revision controllers
packagist
statamic/cms
Moderate
2 months ago
Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
packagist
statamic/cms
Moderate
2 months ago
Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential
packagist
statamic/cms
Moderate
2 months ago
Statamic's live preview token bypasses content protection for unrelated entries
packagist
statamic/cms
Moderate
2 months ago
Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag
packagist
statamic/cms
Moderate
2 months ago
Statamic's Markdown preview endpoint exposes sensitive user data
packagist
statamic/cms
Moderate
3 months ago
Statamic is missing authorization check on taxonomy term creation via fieldtype
packagist
statamic/cms
Moderate
3 months ago
Statamic has a path traversal in file dictionary fieldtype
packagist
statamic/cms
Moderate
3 months ago
Statamic vulnerable to privilege escalation via stored cross-site scripting
packagist
statamic/cms
High
3 months ago
Statamic vulnerable to privilege escalation via stored cross-site scripting
packagist
statamic/cms
High
3 months ago
Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs
packagist
statamic/cms
Moderate
3 months ago
Statamic's missing authorization allows access to email addresses
packagist
statamic/cms
Moderate
3 months ago
Statamic Vulnerable to Server-Side Request Forgery via Glide
packagist
statamic/cms
High
3 months ago
Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
packagist
statamic/cms
Critical
3 months ago
Statamic is vulnerable to account takeover via password reset link injection
packagist
statamic/cms
High
3 months ago
Statamic affected by privilege escalation via stored cross-site scripting
packagist
statamic/cms
High
4 months ago
Statamic CMS vulnerable to privilege escalation via stored cross-site scripting
packagist
statamic/cms
Moderate
4 months ago
Statamic CMS's missing authorization allows access to assets
packagist
statamic/cms
High
7 months ago
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
packagist
statamic/cms
Low
almost 2 years ago
Password confirmation stored in plain text via registration form in statamic/cms
packagist
statamic/cms
High
over 2 years ago
Statmic CMS vulnerable to account takeover via XSS and password reset link
packagist
statamic/cms
High
over 2 years ago
Statamic CMS vulnerable to remote code execution via form uploads
packagist
statamic/cms
High
over 2 years ago
Statamic CMS remote code execution via front-end form uploads
packagist
statamic/cms
Moderate
almost 3 years ago
Statamic's Antlers sanitizer cannot effectively sanitize malicious SVG
packagist
statamic/cms