Statamic cms是美国Statamic公司的一个内容管理系统。 Statamic CMS 5.74.1之前版本和6.24.0之前版本存在安全漏洞,该漏洞源于访问控制不当,可能导致已认证的控制面板用户通过用于创建用户的端点判断给定邮箱地址是否属于现有用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64665 | 8.1 HIGH | Statamic: Account takeover via OAuth email matching without email-verification check |
| CVE-2026-64662 | 6.5 MEDIUM | Statamic: Missing authorization on navigation endpoint allows disclosure of restricted ent |
| CVE-2026-64663 | 6.5 MEDIUM | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction |
| CVE-2026-71435 | 6.1 MEDIUM | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template |
| CVE-2026-71434 | 5.3 MEDIUM | Statamic: Missing file upload validation on frontend forms allows uploading disallowed fil |
No comments yet