statamic has 11 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 11 prev 0
Weakness classes
Products
- statamic/cms 11
Worst active — by depth score
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)45CVE-2026-49287High· 7.4Statamic CMS's unsafe method invocation via collection sorting allows data destruction41CVE-2026-64663Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)36CVE-2026-64662Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)36CVE-2026-71435Medium· 6.1Statamic is a Laravel and Git powered content management system (CMS)34
statamic vulnerabilities
CVEs affecting statamic, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-64664Medium· 4.3Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…
CVE-2026-64663Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…
CVE-2026-64662Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…
CVE-2026-71434Medium· 5.3Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could up…
CVE-2026-71435Medium· 6.1Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submit…
CVE-2026-49288Medium· 4.3Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
CVE-2026-49287High· 7.4Statamic CMS's unsafe method invocation via collection sorting allows data destruction
Statamic CMS's unsafe method invocation via collection sorting allows data destruction
CVE-2026-54242Medium· 4.9Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-54243Medium· 6.1Statamic Vulnerable to CSV formula injection in form submission exports
Statamic Vulnerable to CSV formula injection in form submission exports
CVE-2026-54244Low· 3.5Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors