Security: statamic/cms
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unsafe method invocation via Antlers template resolution allows account takeover and data destructionGHSA-33fx-2776-vvp5 published
Aug 14, 2026 by jasonvargaHigh -
SVG sanitization bypassed for uploads whose file extension is not normalizedGHSA-7qmf-j24c-x6cx published
Aug 14, 2026 by jasonvargaModerate -
Missing file upload validation on frontend forms allows uploading disallowed file typesGHSA-qhr7-v3xp-vw9m published
Jul 9, 2026 by jasonvargaModerate -
Stored Cross-Site Scripting in Automagic Form Notification Email TemplateGHSA-vx89-p3j7-8xqc published
Jul 9, 2026 by jasonvargaModerate -
Missing authorization on navigation endpoint allows disclosure of restricted entriesGHSA-qh8c-7588-qfrv published
Jul 2, 2026 by jasonvargaModerate -
Unsafe method invocation via Antlers template resolution allows data destructionGHSA-j2vp-f2pv-5rj4 published
Jul 2, 2026 by jasonvargaModerate -
Missing authorization on Control Panel endpoint allows disclosure of user existenceGHSA-225x-3jhx-wh4q published
Jul 2, 2026 by jasonvargaModerate -
Account takeover via OAuth email matching without email-verification checkGHSA-93qh-5269-9wcf published
Jul 2, 2026 by jasonvargaHigh -
Incorrect authorization lets view-only users submit Live Preview content reserved for editorsGHSA-7mqq-4v55-88gh published
Jun 9, 2026 by jasonvargaLow -
CSV formula injection in form submission exportsGHSA-h77m-qrj7-jxcw published
Jun 3, 2026 by jasonvargaModerate