Statamic cms是美国Statamic公司的一个内容管理系统。 Statamic CMS 5.74.1之前版本和6.24.0之前版本存在授权问题漏洞,该漏洞源于导航端点存在权限验证不当,已认证的控制面板用户可查看其无权查看的条目内容,包括自定义字段值和未发布条目,但无法修改数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64665 | 8.1 HIGH | Statamic: Account takeover via OAuth email matching without email-verification check |
| CVE-2026-64663 | 6.5 MEDIUM | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction |
| CVE-2026-71435 | 6.1 MEDIUM | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template |
| CVE-2026-71434 | 5.3 MEDIUM | Statamic: Missing file upload validation on frontend forms allows uploading disallowed fil |
| CVE-2026-64664 | 4.3 MEDIUM | Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existe |
No comments yet