<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Statamic</title>
  <link>https://cvedaily.com/pages/tags/statamic.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/statamic.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Statamic</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-45660 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45660</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45660</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed using an IP representation that wasn't normalized before the public-IP check. An unauthenticated user could cause the server to make HTTP requests to internal addresses — including loopback, private network, and cloud metadata endpoints. This…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44306 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44306</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44306</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could use this to enumerate valid users, which can aid in follow-up credential-based attacks. This vulnerability is fixed in 5.73.21 and 6.15.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41175 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41175</guid>
    <pubDate>Wed, 22 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41175</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33887 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33887</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33887</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the authorization checks that the main entry controllers enforce, exposing entry field values and bluepri…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33886 – Statamic is a Laravel and Git powered content management system (CMS). Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33886</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33886</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33885 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33885</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33885</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33884 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33884</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33884</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33883 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33883</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33883</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser. This has been fixed in 5.73.16 and 6.7.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33882 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33882</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33882</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, an authenticated control panel user could retrieve sensitive user data including email addresses, encrypted passkey data, and encrypted two-factor au…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33177 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33177</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33177</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileged Control Panel users could create taxonomy terms by submitting requests to the field action processing endpoint with attacker-controlled field definitions. This bypasses the authorization checks enforced on the standard taxonomy term creation endpoint. This has been fixed in 5…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33172 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33172</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33172</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that executes when the asset is viewed. This has been fixed in 5.73.14 and 6.7.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33171 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33171</guid>
    <pubDate>Fri, 20 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33171</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration parameter in the fieldtype's endpoint. This has been fixed in 5.73.14 and 6.7.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32612 – Statamic is a Laravel and Git powered content management system (CMS). Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32612</guid>
    <pubDate>Fri, 13 Mar 2026 19:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32612</strong></p>
  <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. This has been fixed in 6.6.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28425 – Statmatic is a Laravel and Git powered content management system (CMS). Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28425</guid>
    <pubDate>Fri, 27 Feb 2026 23:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28425</strong></p>
  <p>Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the application, including access to sensitive configuration, modification or exfiltration of data, and pot…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25633 – Statamic is a, Laravel + Git powered CMS designed for building websites. Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25633</guid>
    <pubDate>Wed, 11 Feb 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25633</strong></p>
  <p>Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60868 – The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query stri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60868</guid>
    <pubDate>Fri, 10 Oct 2025 14:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60868</strong></p>
  <p>The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-9322 – The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9322</guid>
    <pubDate>Fri, 08 Aug 2025 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-9322</strong></p>
  <p>The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-36119 – Statamic is a, Laravel + Git powered CMS designed for building websites. In affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36119</guid>
    <pubDate>Thu, 30 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-36119</strong></p>
  <p>Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the following conditions: 1. Running Statamic versions between 5.3.0 and 5.6.1. (This version range represents only one calendar we…</p>
  <p><strong>CVSS:</strong> 1.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24570 – Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24570</guid>
    <pubDate>Thu, 01 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24570</strong></p>
  <p>Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the control panel. Additionally, if the XSS is crafted in a specific way, the "copy password reset link" feature may be exploited…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48701 – Statamic CMS is a Laravel and Git powered content management system (CMS). Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48701</guid>
    <pubDate>Tue, 21 Nov 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48701</strong></p>
  <p>Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control panel which requires authentication. This issue has been patched on 3.4.15 and 4.36…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48217 – Statamic is a flat-first, Laravel + Git powered CMS designed for building websit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48217</guid>
    <pubDate>Tue, 14 Nov 2023 22:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48217</strong></p>
  <p>Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fields in the control panel. Malicious users could leverage this vulnerability to upload and execute code.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36828 – Statamic is a flat-first, Laravel and Git powered content management system. Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36828</guid>
    <pubDate>Wed, 05 Jul 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36828</strong></p>
  <p>Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-24784 – Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24784</guid>
    <pubDate>Fri, 25 Mar 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-24784</strong></p>
  <p>Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45364 – A Code Execution vulnerability exists in Statamic Version through 3.2.26 via Set...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45364</guid>
    <pubDate>Thu, 10 Feb 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45364</strong></p>
  <p>A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-19598 – Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an '...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19598</guid>
    <pubDate>Wed, 19 Dec 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-19598</strong></p>
  <p>Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-11422 – Statamic framework before 2.6.0 does not correctly check a session's permissions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11422</guid>
    <pubDate>Mon, 24 Jul 2017 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-11422</strong></p>
  <p>Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11422">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
