ZeroHour

Vulnerabilities

29 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41175
Statamic is a Laravel and Git powered content management system (CMS).

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to delete entries, or "view users" permission to delete users, etc. The REST and GraphQL API exploits do not require any permissions, however neither are enabled by default. In order to be exploited, they would need to be explicitly enabled with no authentication configured, and the specific resources enabled too. Sites that enable the REST or GraphQL API without authentication should treat patching as critical priority. This has been fixed in 5.73.20 and 6.13.0.

NVD description · AI analysis pending
8.1<1%
  • statamic statamic
CVE-2026-33882
Statamic is a Laravel and Git powered content management system (CMS).

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, an authenticated control panel user could retrieve sensitive user data including email addresses, encrypted passkey data, and encrypted two-factor authentication codes. This has been fixed in 5.73.16 and 6.7.2.

NVD description · AI analysis pending
6.5
group max
<1%
  • statamic statamic
CVE-2026-33172
+2 in the same advisory: …33171 …33177
Statamic is a Laravel and Git powered content management system (CMS).

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that executes when the asset is viewed. This has been fixed in 5.73.14 and 6.7.0.

NVD description · AI analysis pending
8.7
group max
<1%
  • statamic statamic
CVE-2026-32612
Statamic is a Laravel and Git powered content management system (CMS).

Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. This has been fixed in 6.6.2.

NVD description · AI analysis pending
5.4<1% PoC
  • statamic statamic
CVE-2026-27939
+4 in the same advisory: …28423 …28425 …28424 …28426
Statmatic is a Laravel and Git powered content management system (CMS).

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.

NVD description · AI analysis pending
8.8
group max
<1%
  • statamic statamic
CVE-2026-27593
Statmatic is a Laravel and Git powered content management system (CMS).

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account on the site, and the actual user must blindly click the link in their email even though they didn't request the reset. This has been fixed in 6.3.3 and 5.73.10.

NVD description · AI analysis pending
8.8<1%
  • statamic statamic
CVE-2026-27196
Statmatic is a Laravel and Git powered content management system (CMS).

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This issue has been fixed in 6.3.2 and 5.73.9.

NVD description · AI analysis pending
4.8<1%
  • statamic statamic
CVE-2026-25759
+1 in the same advisory: …25633
Statmatic is a Laravel and Git powered content management system (CMS).

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an account with control panel access and content creation permissions. This vulnerability can be exploited to allow super admin accounts to be created. This has been fixed in 6.2.3.

NVD description · AI analysis pending
8.7
group max
<1%
  • statamic statamic
CVE-2024-24570
Statamic is a Laravel and Git powered CMS.

Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the control panel. Additionally, if the XSS is crafted in a specific way, the "copy password reset link" feature may be exploited to gain access to a user's password reset token and gain access to their account. The authorized user is required to execute the XSS in order for the vulnerability to occur. In versions 4.46.0 and 3.4.17, the XSS vulnerability has been patched, and the copy password reset link functionality has been disabled.

NVD description · AI analysis pending
6.1<1%
  • statamic statamic
CVE-2023-48701
Statamic CMS is a Laravel and Git powered content management system (CMS).

Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication. This issue has been patched on 3.4.15 and 4.36.0.

NVD description · AI analysis pending
6.1<1%
  • statamic statamic
CVE-2023-48217
Statamic is a flat-first, Laravel + Git powered CMS designed for building websites.

Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fields in the control panel. Malicious users could leverage this vulnerability to upload and execute code. This issue has been patched in versions 3.4.14 and 4.34.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
8.81%
  • statamic statamic
CVE-2023-47129
Statmic is a core Laravel content management system Composer package.

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.

NVD description · AI analysis pending
9.81%
  • statamic statamic
CVE-2023-36828
Statamic is a flat-first, Laravel and Git powered content management system.

Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue.

NVD description · AI analysis pending
5.4<1% PoC
  • statamic statamic
CVE-2022-24784
Statamic is a Laravel and Git powered CMS.

Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.

NVD description · AI analysis pending
3.71%
  • statamic statamic
CVE-2021-45364
A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php.

A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product

NVD description · AI analysis pending
9.82% PoC
  • statamic statamic
CVE-2018-19598
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

NVD description · AI analysis pending
4.8<1% PoC
  • statamic statamic
CVE-2017-11422
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called.

Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.

NVD description · AI analysis pending
8.8<1%
  • statamic statamic