Statamic是美国Statamic公司的一个基于 Laravel 构建的强大的平面文件 Cms。用于将所有内容、模板、资产和设置存储在文件而不是数据库中。 Statamic 5.73.16之前版本和6.7.2之前版本存在信息泄露漏洞,该漏洞源于markdown预览端点可能被操纵以返回任意字段类型的增强数据,可能导致经过身份验证的控制面板用户检索敏感用户数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33886 | 6.5 MEDIUM | Statamic's sensitive configuration values are exposed to content editors via Antlers-enabl |
| CVE-2026-33883 | 6.1 MEDIUM | Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag |
| CVE-2026-33885 | 6.1 MEDIUM | Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential |
| CVE-2026-33887 | 5.4 MEDIUM | Statamic allows unauthorized content access through missing authorization in its revision |
| CVE-2026-33884 | 4.3 MEDIUM | Statamic's live preview token bypasses content protection for unrelated entries |
No comments yet