Statamic cms是美国Statamic公司的一个内容管理系统。 Statamic CMS 5.74.3之前版本和6.24.2之前版本存在任意文件上传漏洞,该漏洞源于公共前端表单未强制执行控制面板的文件上传限制,可能导致未经身份验证的访问者上传管理员禁止的文件类型,并存储在公开可访问的磁盘上。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64665 | 8.1 HIGH | Statamic: Account takeover via OAuth email matching without email-verification check |
| CVE-2026-64662 | 6.5 MEDIUM | Statamic: Missing authorization on navigation endpoint allows disclosure of restricted ent |
| CVE-2026-64663 | 6.5 MEDIUM | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction |
| CVE-2026-71435 | 6.1 MEDIUM | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template |
| CVE-2026-64664 | 4.3 MEDIUM | Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existe |
No comments yet