Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2241985
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048510
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68975
Echo
7872
GHC
3
GIT
109056
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148539
npm
229211
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7101
Pub
11
PyPI
25464
Red Hat
23535
Rocky Linux
4343
Root
19643
RubyGems
5369
SUSE
23442
SwiftURL
60
TuxCare
9951
Ubuntu
66085
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vx89-p3j7-8xqc
Packagist/statamic/cms
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
06 Aug
Fix available
Severity - 6.1 (Medium)
GHSA-qhr7-v3xp-vw9m
Packagist/statamic/cms
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
06 Aug
Fix available
Severity - 5.3 (Medium)
GHSA-qh8c-7588-qfrv
Packagist/statamic/cms
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
06 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-j2vp-f2pv-5rj4
Packagist/statamic/cms
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
06 Aug
Fix available
Severity - 6.5 (Medium)
GHSA-93qh-5269-9wcf
Packagist/statamic/cms
Statamic: Account takeover via OAuth email matching without email-verification check
06 Aug
Fix available
Severity - 8.1 (High)
GHSA-225x-3jhx-wh4q
Packagist/statamic/cms
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
06 Aug
Fix available
Severity - 4.3 (Medium)
GHSA-jppw-r5j3-xf7x
Packagist/statamic/cms
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering
05 Aug
No fix available
Severity - 6.2 (Medium)
GHSA-7mqq-4v55-88gh
Packagist/statamic/cms
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
26 Jun
Fix available
Severity - 3.5 (Low)
GHSA-h77m-qrj7-jxcw
Packagist/statamic/cms
Statamic Vulnerable to CSV formula injection in form submission exports
26 Jun
Fix available
Severity - 6.1 (Medium)
GHSA-v5c4-wcpj-x73m
Packagist/statamic/cms
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
26 Jun
Fix available
Severity - 4.9 (Medium)
GHSA-m92m-r54r-x8r2
Packagist/statamic/cms
Statamic CMS's unsafe method invocation via collection sorting allows data destruction
26 Jun
Fix available
Severity - 7.4 (High)
GHSA-2497-6pwj-pwg7
Packagist/statamic/cms
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
26 Jun
Fix available
Severity - 4.3 (Medium)
GHSA-pf9c-ch8r-2958
Packagist/statamic/cms
Statamic CMS: Server-Side Request Forgery via Glide
18 May
Fix available
Severity - 5.4 (Medium)
GHSA-m24v-f7g5-gq67
Packagist/statamic/cms
Statamic CMS vulnerable to email enumeration via forgot password endpoint
06 May
Fix available
Severity - 5.3 (Medium)
GHSA-4jjr-vmv7-wh4w
Packagist/statamic/cms
Statamic: Unsafe method invocation via query value resolution allows data destruction
16 Apr
Fix available
Severity - 8.1 (High)
GHSA-4hp7-3wxg-cv9q
Packagist/statamic/cms
Statamic allows unauthorized content access through missing authorization in its revision controllers
26 Mar
Fix available
Severity - 5.4 (Medium)
Load more...
Packagist - OSV