Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Statamic

First CVE: Jul 24, 2017Active for: 9 yearsTotal CVEs: 29
26.9
VTI Score
Low

Statamic is a modestly represented content-management system and flat-file or database-backed web platform positioned among more prominent vendors in the vulnerability landscape. Vulnerabilities affecting the vendor concentrate in a single flagship product and lean toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure centers on web-application layer weaknesses including cross-site scripting, missing authorization checks, sensitive-information disclosure, and code-injection conditions that reflect the authorization and input-handling demands of a content-publishing platform. Defenders deploying Statamic should prioritize tracking the vendor's security advisories and patching authorization and injection-class flaws; live severity and current exploitation indicators are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
4.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Statamic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 24, 2017
8 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27593HIGH
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature
Feb 24, 20268.831NONO
CVE-2026-27939HIGH
Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain co
Feb 27, 20268.830NONO
CVE-2026-41175HIGH
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints,
Apr 22, 20268.129NONO
CVE-2026-33172HIGH
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated u
Mar 20, 20268.729NONO
CVE-2026-28425HIGH
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inpu
Feb 27, 20268.029NONO
CVE-2023-47129CRITICAL
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look
Nov 10, 20239.829NONO
CVE-2026-25759HIGH
Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with con
Feb 11, 20268.728NONO
CVE-2023-48217HIGH
Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded re
Nov 14, 20238.826NONO
CVE-2026-28423HIGH
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not th
Feb 27, 20268.625NONO
CVE-2021-45364CRITICAL
A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Recor
Feb 10, 20229.824NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
59%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network29 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (96.6%)
High1 (3.4%)
Unknown0 (0.0%)
User Interaction
None16 (55.2%)
Unknown0 (0.0%)
Required13 (44.8%)
Privileges Required
Low18 (62.1%)
High2 (6.9%)
None9 (31.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Statamic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Statamic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Statamic's Products

View all 2 CNAs →

Top CWEs