PatchSiren

statamic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH statamic CVE published 2026-08-06

CVE-2026-64665

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-64665 is a vulnerability in Statamic, a Laravel and Git powered content management system (CMS). The issue arises when OAuth login is enabled with a provider that does not guarantee verified email addresses, allowing an unauthenticated attacker to sign in as an existing user, potentially including a super admin, without knowing t [truncated]

MEDIUM statamic CVE published 2026-08-05

CVE-2026-71293

The CVE-2026-71293 vulnerability affects Statamic CMS's AugmentedUser resolver, allowing attackers to obtain 2FA recovery codes via dynamic Antlers template rendering. This vulnerability exists because two_factor_recovery_codes is neither excluded from augmentation nor present in Statamic's Antlers variable guard lists. The likely operational impact includes 2FA bypass and potential unauthorized access to [truncated]

LOW statamic CVE published 2026-07-17

CVE-2026-54244

A Control Panel user with view but not edit permission could submit content they were not authorized to author and generate a shareable Live Preview URL rendering it due to insufficient authorization checks in the Live Preview endpoint. This vulnerability affects Statamic CMS versions prior to 5.74.0 and 6.20.3. The issue allows unauthorized content submission and preview, potentially leading to informati [truncated]

MEDIUM statamic CVE published 2026-07-17

CVE-2026-54242

CVE-2026-54242 is a medium-severity vulnerability affecting Statamic, a Laravel and Git powered content management system (CMS). The Glide image proxy's URL validation could be bypassed using DNS rebinding, allowing an attacker to make HTTP requests to internal addresses. This vulnerability exists in src/Imaging/RemoteUrlValidator.php and src/Imaging/GuzzleAdapter.php. An attacker controlling the hostname [truncated]

HIGH statamic CVE published 2026-06-19

CVE-2026-49287

CVE-2026-49287 is a HIGH-severity vulnerability in Statamic CMS, with a CVSS score of 7.4. The issue is an incomplete fix for CVE-2026-41175, allowing for loss of content and assets by manipulating sort parameters in a front-end template. This requires a template explicitly set up to sort by a visitor-controlled value. The vulnerability was published on June 19, 2026, and affects Statamic CMS versions pri [truncated]

MEDIUM statamic CVE published 2026-05-29

CVE-2026-45660

Statamic CMS versions prior to 5.73.22 and 6.18.1 contain a Server-Side Request Forgery (SSRF) vulnerability in the Glide image proxy component. The vulnerability exists because URL validation for the Glide image proxy did not properly normalize IP address representations before checking whether they resolve to public IP addresses. This validation bypass allows unauthenticated attackers to supply URLs tha [truncated]