Technology · Packagist
statamic/cms (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in statamic/cms (Packagist): 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-71293, was published on 5 August 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About statamic/cms (Packagist)
A flat-first content management system built on Laravel.
Latest statamic/cms (Packagist) vulnerabilities
- CVE-2026-71293: Statamic CMS two-factor recovery code exposure in Antlers templatesmediumCVSS 6.2EPSS 0.4%
- CVE-2026-32612: Statamic vulnerable to privilege escalation via stored cross-site scriptinglowCVSS 3.1EPSS 0.3%
- CVE-2026-27939: Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypasslowCVSS 3.1EPSS 0.5%
- CVE-2026-25759: Statamic CMS vulnerable to privilege escalation via stored cross-site scriptinglowCVSS 3.1EPSS 0.4%
- CVE-2025-64112: Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN…lowCVSS 3.1EPSS 0.3%
- CVE-2024-52600: Statamic CMS has a Path Traversal in Asset UploadlowCVSS 3.1EPSS 0.6%
- CVE-2024-36119: Password confirmation stored in plain text via registration form in statamic/cmslowCVSS 3.1EPSS 0.1%
- CVE-2023-36828: Statamic's Antlers sanitizer cannot effectively sanitize malicious SVGlowCVSS 3.1EPSS 0.7%
- CVE-2017-11422: Statamic framework Incorrect Permission AssignmentlowCVSS 3.1EPSS 0.9%
Most severe statamic/cms (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-71293: Statamic CMS two-factor recovery code exposure in Antlers templatesmediumCVSS 6.2EPSS 0.4%
- CVE-2017-11422: Statamic framework Incorrect Permission AssignmentlowCVSS 3.1EPSS 0.9%
- CVE-2023-36828: Statamic's Antlers sanitizer cannot effectively sanitize malicious SVGlowCVSS 3.1EPSS 0.7%
- CVE-2024-52600: Statamic CMS has a Path Traversal in Asset UploadlowCVSS 3.1EPSS 0.6%
- CVE-2026-27939: Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypasslowCVSS 3.1EPSS 0.5%
- CVE-2026-25759: Statamic CMS vulnerable to privilege escalation via stored cross-site scriptinglowCVSS 3.1EPSS 0.4%
- CVE-2025-64112: Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN…lowCVSS 3.1EPSS 0.3%
- CVE-2026-32612: Statamic vulnerable to privilege escalation via stored cross-site scriptinglowCVSS 3.1EPSS 0.3%
- CVE-2024-36119: Password confirmation stored in plain text via registration form in statamic/cmslowCVSS 3.1EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/statamic-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "statamic/cms (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/statamic-cms, 27 September 2026.