<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Statamic (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/statamic.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/statamic-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Statamic (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41175 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41175</guid>
    <pubDate>Wed, 22 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41175</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33172 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33172</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33172</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that executes when the asset is viewed. This has been fixed in 5.73.14 and 6.7.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28425 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28425</guid>
    <pubDate>Fri, 27 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28425</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the application, including access to sensitive configuration, modification or exfiltration of data, and pot…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9322 – The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9322</guid>
    <pubDate>Fri, 08 Aug 2025 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9322</strong></p>
  <p>The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24570 – Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24570</guid>
    <pubDate>Thu, 01 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24570</strong></p>
  <p>Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the control panel. Additionally, if the XSS is crafted in a specific way, the "copy password reset link" feature may be exploited…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48701 – Statamic CMS is a Laravel and Git powered content management system (CMS). Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48701</guid>
    <pubDate>Tue, 21 Nov 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48701</strong></p>
  <p>Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication. This issue has been patched on 3.4.15 and 4.36…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48217 – Statamic is a flat-first, Laravel + Git powered CMS designed for building websit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48217</guid>
    <pubDate>Tue, 14 Nov 2023 22:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48217</strong></p>
  <p>Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fields in the control panel. Malicious users could leverage this vulnerability to upload and execute code.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45364 – A Code Execution vulnerability exists in Statamic Version through 3.2.26 via Set...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45364</guid>
    <pubDate>Thu, 10 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45364</strong></p>
  <p>A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-11422 – Statamic framework before 2.6.0 does not correctly check a session's permissions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11422</guid>
    <pubDate>Mon, 24 Jul 2017 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-11422</strong></p>
  <p>Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11422">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
