Statamic is a modestly represented content-management system and flat-file or database-backed web platform positioned among more prominent vendors in the vulnerability landscape. Vulnerabilities affecting the vendor concentrate in a single flagship product and lean toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure centers on web-application layer weaknesses including cross-site scripting, missing authorization checks, sensitive-information disclosure, and code-injection conditions that reflect the authorization and input-handling demands of a content-publishing platform. Defenders deploying Statamic should prioritize tracking the vendor's security advisories and patching authorization and injection-class flaws; live severity and current exploitation indicators are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Statamic over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27593HIGH Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature | Feb 24, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-27939HIGH Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain co | Feb 27, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-41175HIGH Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, | Apr 22, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-33172HIGH Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated u | Mar 20, 2026 | 8.7 | 29 | NO | NO |
CVE-2026-28425HIGH Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inpu | Feb 27, 2026 | 8.0 | 29 | NO | NO |
CVE-2023-47129CRITICAL Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look | Nov 10, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-25759HIGH Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with con | Feb 11, 2026 | 8.7 | 28 | NO | NO |
CVE-2023-48217HIGH Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded re | Nov 14, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-28423HIGH Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not th | Feb 27, 2026 | 8.6 | 25 | NO | NO |
CVE-2021-45364CRITICAL A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Recor | Feb 10, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Statamic.
Media articles that mention a CVE ID that affects a product developed by Statamic — matched by CVE ID, not by vendor name.