statamic/cms Security Advisories for v4.14.0 (13)
-
[HIGH] Statamic vulnerable to privilege escalation via stored cross-site scripting
PKSA-81wb-3yhb-txs4 CVE-2026-28426 GHSA-5vrj-wf7v-5wr7
Affected version: >=6.0.0-alpha.1,<6.4.0|<5.73.11
Reported by:
GitHub -
[HIGH] Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs
PKSA-skzr-by55-tmc5 CVE-2026-28425 GHSA-cpv7-q2wx-m8rw
Affected version: >=6.0.0-alpha.1,<6.4.0|<5.73.11
Reported by:
GitHub -
[MEDIUM] Statamic's missing authorization allows access to email addresses
PKSA-hycr-3628-cp88 CVE-2026-28424 GHSA-w878-f8c6-7r63
Affected version: >=6.0.0-alpha.1,<6.4.0|<5.73.11
Reported by:
GitHub -
[MEDIUM] Statamic Vulnerable to Server-Side Request Forgery via Glide
PKSA-n7ys-rxzm-bn18 CVE-2026-28423 GHSA-cwpp-325q-2cvp
Affected version: >=6.0.0-alpha.1,<6.4.0|<5.73.11
Reported by:
GitHub -
[CRITICAL] Statamic is vulnerable to account takeover via password reset link injection
PKSA-w3y4-x9d3-9t28 CVE-2026-27593 GHSA-jxq9-79vj-rgvw
Affected version: >=6.0.0-alpha.1,<6.3.3|<5.73.10
Reported by:
GitHub -
[HIGH] Statamic affected by privilege escalation via stored cross-site scripting
PKSA-vfrr-bp4n-314v CVE-2026-27196 GHSA-8r7r-f4gm-wcpq
Affected version: <5.73.9|>=6.0.0-alpha.1,<6.3.2
Reported by:
GitHub -
[MEDIUM] Statamic CMS's missing authorization allows access to assets
PKSA-nr63-r5tp-xby1 CVE-2026-25633 GHSA-gwmx-9gcj-332h
Affected version: >=6.0.0-alpha.1,<6.2.5|<5.73.6
Reported by:
GitHub -
[HIGH] Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
PKSA-mmp9-wb2h-d8gy CVE-2025-64112 GHSA-g59r-24g3-h7cm
Affected version: <=5.22.0
Reported by:
GitHub -
[MEDIUM] Statamic CMS has a Path Traversal in Asset Upload
PKSA-8gf5-xvpy-gbms CVE-2024-52600 GHSA-p7f6-8mcm-fwv3
Affected version: <=5.16.0
Reported by:
GitHub -
[HIGH] Statmic CMS vulnerable to account takeover via XSS and password reset link
PKSA-8pw7-xndm-5j7f CVE-2024-24570 GHSA-vqxq-hvxw-9mv9
Affected version: <3.4.17|>=4.00,<4.46.0
Reported by:
GitHub -
[HIGH] Cross-site Scripting via uploaded assets
PKSA-jwp2-xxh9-t8xp CVE-2023-48701 GHSA-8jjh-j3c2-cjcv
Affected version: >=4.0.0,<4.36.0|<3.4.15
Reported by:
GitHub -
[HIGH] Statamic CMS vulnerable to remote code execution via form uploads
PKSA-8hch-61s9-d7gd CVE-2023-48217 GHSA-2r53-9295-3m86
Affected version: <3.4.14|>=4.0.0,<4.34.0
Reported by:
GitHub -
[HIGH] Statamic CMS remote code execution via front-end form uploads
PKSA-tcb6-sf7c-j9gd CVE-2023-47129 GHSA-72hg-5wr5-rmfc
Affected version: <3.4.13|>=4.0.0,<4.33.0
Reported by:
GitHub