Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vx89-p3j7-8xqc
  • Packagist/statamic/cms
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template 06 Aug
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-qhr7-v3xp-vw9m
  • Packagist/statamic/cms
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types 06 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-qh8c-7588-qfrv
  • Packagist/statamic/cms
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries 06 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-j2vp-f2pv-5rj4
  • Packagist/statamic/cms
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction 06 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-93qh-5269-9wcf
  • Packagist/statamic/cms
Statamic: Account takeover via OAuth email matching without email-verification check 06 Aug
  • Fix available
  • Severity - 8.1 (High)
GHSA-225x-3jhx-wh4q
  • Packagist/statamic/cms
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence 06 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-jppw-r5j3-xf7x
  • Packagist/statamic/cms
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering 05 Aug
  • No fix available
  • Severity - 6.2 (Medium)
GHSA-7mqq-4v55-88gh
  • Packagist/statamic/cms
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors 26 Jun
  • Fix available
  • Severity - 3.5 (Low)
GHSA-h77m-qrj7-jxcw
  • Packagist/statamic/cms
Statamic Vulnerable to CSV formula injection in form submission exports 26 Jun
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-v5c4-wcpj-x73m
  • Packagist/statamic/cms
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding) 26 Jun
  • Fix available
  • Severity - 4.9 (Medium)
GHSA-m92m-r54r-x8r2
  • Packagist/statamic/cms
Statamic CMS's unsafe method invocation via collection sorting allows data destruction 26 Jun
  • Fix available
  • Severity - 7.4 (High)
GHSA-2497-6pwj-pwg7
  • Packagist/statamic/cms
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources 26 Jun
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-pf9c-ch8r-2958
  • Packagist/statamic/cms
Statamic CMS: Server-Side Request Forgery via Glide 18 May
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-m24v-f7g5-gq67
  • Packagist/statamic/cms
Statamic CMS vulnerable to email enumeration via forgot password endpoint 06 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-4jjr-vmv7-wh4w
  • Packagist/statamic/cms
Statamic: Unsafe method invocation via query value resolution allows data destruction 16 Apr
  • Fix available
  • Severity - 8.1 (High)
GHSA-4hp7-3wxg-cv9q
  • Packagist/statamic/cms
Statamic allows unauthorized content access through missing authorization in its revision controllers 26 Mar
  • Fix available
  • Severity - 5.4 (Medium)