{"schema_version":1,"title":"Statamic vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in Statamic: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-64665, was published on 6 August 2026.","url":"https://junglewise.ai/threats/technologies/statamic","json_url":"https://junglewise.ai/threats/technologies/statamic.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/statamic","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":14},"latest":[{"cve":"CVE-2026-64665","cvss":8.1,"epss":0.0054,"slug":"cve-2026-64665-statamic-cms-account-takeover-via-oauth-email-matching","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provi","severity":"high","exploited":false,"published_at":"2026-08-06T22:18:14.103+00:00","url":"https://junglewise.ai/threats/cve-2026-64665-statamic-cms-account-takeover-via-oauth-email-matching"},{"cve":"CVE-2026-64664","cvss":4.3,"epss":0.0034,"slug":"cve-2026-64664-statamic-cms-missing-authorization-in-control-panel-user-wizard","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could","severity":"medium","exploited":false,"published_at":"2026-08-06T22:18:13.96+00:00","url":"https://junglewise.ai/threats/cve-2026-64664-statamic-cms-missing-authorization-in-control-panel-user-wizard"},{"cve":"CVE-2026-64663","cvss":6.5,"epss":0.004,"slug":"cve-2026-64663-statamic-cms-unsafe-reflection-in-antlers-template-resolution","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorpor","severity":"medium","exploited":false,"published_at":"2026-08-06T22:18:13.82+00:00","url":"https://junglewise.ai/threats/cve-2026-64663-statamic-cms-unsafe-reflection-in-antlers-template-resolution"},{"cve":"CVE-2026-64662","cvss":6.5,"epss":0.0042,"slug":"cve-2026-64662-statamic-cms-missing-authorization-in-navigation-endpoint","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could","severity":"medium","exploited":false,"published_at":"2026-08-06T22:18:13.673+00:00","url":"https://junglewise.ai/threats/cve-2026-64662-statamic-cms-missing-authorization-in-navigation-endpoint"},{"cve":"CVE-2026-71435","cvss":6.1,"epss":0.0034,"slug":"cve-2026-71435-statamic-cms-stored-xss-in-form-notification-email-template","title":"Statamic CMS stored XSS in form notification email template","severity":"medium","exploited":false,"published_at":"2026-08-06T19:37:58+00:00","url":"https://junglewise.ai/threats/cve-2026-71435-statamic-cms-stored-xss-in-form-notification-email-template"},{"cve":"CVE-2026-71434","cvss":5.3,"epss":0.0041,"slug":"cve-2026-71434-statamic-cms-unrestricted-file-upload-in-frontend-forms","title":"Statamic CMS unrestricted file upload in frontend forms","severity":"medium","exploited":false,"published_at":"2026-08-06T19:35:00+00:00","url":"https://junglewise.ai/threats/cve-2026-71434-statamic-cms-unrestricted-file-upload-in-frontend-forms"},{"cve":"CVE-2026-71293","cvss":6.2,"epss":0.0037,"slug":"cve-2026-71293-statamic-cms-two-factor-recovery-code-exposure-in-antlers","title":"Statamic CMS two-factor recovery code exposure in Antlers templates","severity":"medium","exploited":false,"published_at":"2026-08-05T15:32:21+00:00","url":"https://junglewise.ai/threats/cve-2026-71293-statamic-cms-two-factor-recovery-code-exposure-in-antlers"},{"cve":"CVE-2026-54244","cvss":3.5,"epss":0.003,"slug":"cve-2026-54244-statamic-cms-incorrect-authorization-in-live-preview","title":"Statamic CMS incorrect authorization in Live Preview","severity":"low","exploited":false,"published_at":"2026-07-17T21:17:08.523+00:00","url":"https://junglewise.ai/threats/cve-2026-54244-statamic-cms-incorrect-authorization-in-live-preview"},{"cve":"CVE-2026-54243","cvss":6.1,"epss":0.0034,"slug":"cve-2026-54243-statamic-cms-csv-injection-in-form-submission-exports","title":"Statamic CMS CSV injection in form submission exports","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:08.39+00:00","url":"https://junglewise.ai/threats/cve-2026-54243-statamic-cms-csv-injection-in-form-submission-exports"},{"cve":"CVE-2026-54242","cvss":4.9,"epss":0.0023,"slug":"cve-2026-54242-statamic-cms-ssrf-via-dns-rebinding-in-glide-image-proxy","title":"Statamic CMS SSRF via DNS rebinding in Glide image proxy","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:08.247+00:00","url":"https://junglewise.ai/threats/cve-2026-54242-statamic-cms-ssrf-via-dns-rebinding-in-glide-image-proxy"},{"cve":"CVE-2026-49288","cvss":4.3,"epss":0.0027,"slug":"cve-2026-49288-statamic-cms-incorrect-authorization-in-control-panel-fieldtype","title":"Statamic CMS incorrect authorization in Control Panel fieldtype endpoints","severity":"medium","exploited":false,"published_at":"2026-06-19T19:16:36.04+00:00","url":"https://junglewise.ai/threats/cve-2026-49288-statamic-cms-incorrect-authorization-in-control-panel-fieldtype"},{"cve":"CVE-2026-49287","cvss":7.4,"epss":0.0046,"slug":"cve-2026-49287-statamic-cms-unsafe-reflection-in-collection-sorting","title":"Statamic CMS unsafe reflection in collection sorting","severity":"high","exploited":false,"published_at":"2026-06-19T18:16:19.617+00:00","url":"https://junglewise.ai/threats/cve-2026-49287-statamic-cms-unsafe-reflection-in-collection-sorting"},{"cve":"CVE-2026-45660","cvss":5.4,"epss":0.0024,"slug":"cve-2026-45660-statamic-cms-ssrf-in-glide-image-proxy","title":"Statamic CMS SSRF in Glide image proxy","severity":"medium","exploited":false,"published_at":"2026-05-29T18:17:11.64+00:00","url":"https://junglewise.ai/threats/cve-2026-45660-statamic-cms-ssrf-in-glide-image-proxy"},{"cve":"CVE-2026-44306","cvss":5.3,"epss":0.0035,"slug":"cve-2026-44306-statamic-cms-email-enumeration-in-forgot-password-endpoint","title":"Statamic CMS user enumeration in forgot password form","severity":"medium","exploited":false,"published_at":"2026-05-12T22:16:37.413+00:00","url":"https://junglewise.ai/threats/cve-2026-44306-statamic-cms-email-enumeration-in-forgot-password-endpoint"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Statamic","slug":"statamic","vendor":{"name":"Statamic","slug":"statamic","url":"https://junglewise.ai/threats/vendors/statamic"},"aliases":[],"category":"cms","homepage":"https://statamic.com","description":"A flat-first, Laravel-powered content management system.","url":"https://junglewise.ai/threats/technologies/statamic"},"most_severe":[{"cve":"CVE-2026-64665","cvss":8.1,"epss":0.0054,"slug":"cve-2026-64665-statamic-cms-account-takeover-via-oauth-email-matching","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provi","severity":"high","exploited":false,"published_at":"2026-08-06T22:18:14.103+00:00","url":"https://junglewise.ai/threats/cve-2026-64665-statamic-cms-account-takeover-via-oauth-email-matching"},{"cve":"CVE-2026-49287","cvss":7.4,"epss":0.0046,"slug":"cve-2026-49287-statamic-cms-unsafe-reflection-in-collection-sorting","title":"Statamic CMS unsafe reflection in collection sorting","severity":"high","exploited":false,"published_at":"2026-06-19T18:16:19.617+00:00","url":"https://junglewise.ai/threats/cve-2026-49287-statamic-cms-unsafe-reflection-in-collection-sorting"},{"cve":"CVE-2026-64662","cvss":6.5,"epss":0.0042,"slug":"cve-2026-64662-statamic-cms-missing-authorization-in-navigation-endpoint","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could","severity":"medium","exploited":false,"published_at":"2026-08-06T22:18:13.673+00:00","url":"https://junglewise.ai/threats/cve-2026-64662-statamic-cms-missing-authorization-in-navigation-endpoint"},{"cve":"CVE-2026-64663","cvss":6.5,"epss":0.004,"slug":"cve-2026-64663-statamic-cms-unsafe-reflection-in-antlers-template-resolution","title":"Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorpor","severity":"medium","exploited":false,"published_at":"2026-08-06T22:18:13.82+00:00","url":"https://junglewise.ai/threats/cve-2026-64663-statamic-cms-unsafe-reflection-in-antlers-template-resolution"},{"cve":"CVE-2026-71293","cvss":6.2,"epss":0.0037,"slug":"cve-2026-71293-statamic-cms-two-factor-recovery-code-exposure-in-antlers","title":"Statamic CMS two-factor recovery code exposure in Antlers templates","severity":"medium","exploited":false,"published_at":"2026-08-05T15:32:21+00:00","url":"https://junglewise.ai/threats/cve-2026-71293-statamic-cms-two-factor-recovery-code-exposure-in-antlers"},{"cve":"CVE-2026-71435","cvss":6.1,"epss":0.0034,"slug":"cve-2026-71435-statamic-cms-stored-xss-in-form-notification-email-template","title":"Statamic CMS stored XSS in form notification email template","severity":"medium","exploited":false,"published_at":"2026-08-06T19:37:58+00:00","url":"https://junglewise.ai/threats/cve-2026-71435-statamic-cms-stored-xss-in-form-notification-email-template"},{"cve":"CVE-2026-54243","cvss":6.1,"epss":0.0034,"slug":"cve-2026-54243-statamic-cms-csv-injection-in-form-submission-exports","title":"Statamic CMS CSV injection in form submission exports","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:08.39+00:00","url":"https://junglewise.ai/threats/cve-2026-54243-statamic-cms-csv-injection-in-form-submission-exports"},{"cve":"CVE-2026-45660","cvss":5.4,"epss":0.0024,"slug":"cve-2026-45660-statamic-cms-ssrf-in-glide-image-proxy","title":"Statamic CMS SSRF in Glide image proxy","severity":"medium","exploited":false,"published_at":"2026-05-29T18:17:11.64+00:00","url":"https://junglewise.ai/threats/cve-2026-45660-statamic-cms-ssrf-in-glide-image-proxy"},{"cve":"CVE-2026-71434","cvss":5.3,"epss":0.0041,"slug":"cve-2026-71434-statamic-cms-unrestricted-file-upload-in-frontend-forms","title":"Statamic CMS unrestricted file upload in frontend forms","severity":"medium","exploited":false,"published_at":"2026-08-06T19:35:00+00:00","url":"https://junglewise.ai/threats/cve-2026-71434-statamic-cms-unrestricted-file-upload-in-frontend-forms"},{"cve":"CVE-2026-44306","cvss":5.3,"epss":0.0035,"slug":"cve-2026-44306-statamic-cms-email-enumeration-in-forgot-password-endpoint","title":"Statamic CMS user enumeration in forgot password form","severity":"medium","exploited":false,"published_at":"2026-05-12T22:16:37.413+00:00","url":"https://junglewise.ai/threats/cve-2026-44306-statamic-cms-email-enumeration-in-forgot-password-endpoint"}],"generated_at":"2026-09-26T19:07:00.176898+00:00"}