cms是Statamic开源的一个软件包。 cms 5.73.11之前版本和6.4.0之前版本存在代码问题漏洞,该漏洞源于在不安全模式下使用Glide图像处理时,图像代理可能被滥用以向任意URL发送HTTP请求,可能导致访问内部服务、云元数据端点和其他可从服务器访问的主机。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27939 | 8.8 HIGH | Statamic allows Authenticated Control Panel users to escalate privileges via elevated sess |
| CVE-2026-28426 | 8.7 HIGH | Statamic vulnerable to privilege escalation via stored cross-site scripting |
| CVE-2026-28425 | 8.0 HIGH | Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs |
| CVE-2026-28424 | 6.5 MEDIUM | Statamic's missing authorization allows access to email addresses |
No comments yet