Statamic是美国Statamic公司的一个基于 Laravel 构建的强大的平面文件 Cms。用于将所有内容、模板、资产和设置存储在文件而不是数据库中。 Statamic 5.73.16之前版本和6.7.2之前版本存在安全漏洞,该漏洞源于经过身份验证的控制面板用户可以查看任何启用修订的集合的条目修订,可能导致绕过授权检查并暴露条目字段值和蓝图数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33886 | 6.5 MEDIUM | Statamic's sensitive configuration values are exposed to content editors via Antlers-enabl |
| CVE-2026-33882 | 6.5 MEDIUM | Statamic's Markdown preview endpoint exposes sensitive user data |
| CVE-2026-33883 | 6.1 MEDIUM | Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag |
| CVE-2026-33885 | 6.1 MEDIUM | Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential |
| CVE-2026-33884 | 4.3 MEDIUM | Statamic's live preview token bypasses content protection for unrelated entries |
No comments yet