VulnSea

statamic has 11 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
11 prev 0

Products

  • statamic/cms 11
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

statamic vulnerabilities

CVEs affecting statamic, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-64664Medium· 4.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…

Sunlitstatamic · statamic/cmsEPSS 0.25%via NVD
CVE-2026-64665High· 8.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…

Twilightstatamic · statamic/cmsEPSS 0.31%via NVD
CVE-2026-64663Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…

Sunlitstatamic · statamic/cmsEPSS 0.30%via NVD
CVE-2026-64662Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…

Sunlitstatamic · statamic/cmsEPSS 0.30%via NVD
CVE-2026-71434Medium· 5.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could up…

Sunlitstatamic · statamic/cmsEPSS 0.24%via NVD
CVE-2026-71435Medium· 6.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submit…

Sunlitstatamic · statamic/cmsEPSS 0.19%via NVD
CVE-2026-49288Medium· 4.3
2mo ago

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Sunlitstatamic · statamic/cmsEPSS 0.27%via GHSA
CVE-2026-49287High· 7.4
2mo ago

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

Twilightstatamic · statamic/cmsEPSS 0.46%via GHSA
CVE-2026-54242Medium· 4.9
2mo ago

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Sunlitstatamic · statamic/cmsEPSS 0.23%via GHSA
CVE-2026-54243Medium· 6.1
2mo ago

Statamic Vulnerable to CSV formula injection in form submission exports

Statamic Vulnerable to CSV formula injection in form submission exports

Sunlitstatamic · statamic/cmsEPSS 0.34%via GHSA
CVE-2026-54244Low· 3.5
2mo ago

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Sunlitstatamic · statamic/cmsEPSS 0.30%via GHSA
statamic vulnerabilities (CVEs) · VulnSea