Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2026-41175
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control…
Statamic
5.73.20 / 6.13.0+
MEDIUM 6.5
CVE-2026-33886
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control …
Statamic
5.73.16 / 6.7.2+
MEDIUM 6.1
CVE-2026-33883
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could …
Statamic
5.73.16 / 6.7.2+
MEDIUM 6.1
CVE-2026-33885
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redir…
Statamic
5.73.16 / 6.7.2+
MEDIUM 5.4
CVE-2026-33887
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could v…
Statamic
5.73.16 / 6.7.2+
MEDIUM 6.5
CVE-2026-33882
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be ma…
Statamic
5.73.16 / 6.7.2+
HIGH 8.7
CVE-2026-33172
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…
Statamic
5.73.14 / 6.7.0+
MEDIUM 5.4
CVE-2026-32612
Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows a…
Statamic
6.6.2+
HIGH 8.6
CVE-2026-28423
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in…
Statamic
5.73.11 / 6.4.0+
HIGH 8.0
CVE-2026-28425
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with…
Statamic
5.73.11 / 6.4.0+
MEDIUM 6.5
CVE-2026-28424
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in re…
Statamic
5.73.11 / 6.4.0+
MEDIUM 5.4
CVE-2026-28426
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon…
Statamic
5.73.11 / 6.4.0+
HIGH 8.8
CVE-2026-27939
Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…
Statamic
6.4.0+
HIGH 8.8
CVE-2026-27593
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability…
Statamic
5.73.10 / 6.3.3+
HIGH 8.7
CVE-2026-25759
Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allo…
Statamic
6.2.3+
MEDIUM 6.1
CVE-2024-24570
Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the fron…
Statamic
3.4.17 / 4.46.0+
MEDIUM 6.1
CVE-2023-48701
Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images…
Statamic
3.4.15 / 4.36.0+
HIGH 8.8
CVE-2023-48217
Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…
Statamic
3.4.14 / 4.34.0+
CRITICAL 9.8
CVE-2023-47129
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi…
Statamic
3.4.13 / 4.33.0+
MEDIUM 5.4
CVE-2023-36828
Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Th…
Statamic
4.10.0+
CRITICAL 9.8
CVE-2021-45364
A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an err…
Statamic
after 3.2.26
HIGH 8.8
CVE-2017-11422
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods…
Statamic
2.6.0+