Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.36% | — | Statamic | 27/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This has… | |
| Modificada | Alta (8) | 0.82% | — | Statamic | 27/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the application, including… | |
| Analizada | Media (6.5) | 0.42% | — | Statamic | 27/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0. | |
| Analizada | Alta (8.6) | 0.47% | — | Statamic | 27/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP requests to arbitrary URLs—either via the… | |
| Analizada | Alta (8.8) | 0.46% | — | Statamic | 27/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and,… | |
| Analizada | Alta (8.8) | 0.55% | — | Statamic | 24/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account on the site,… | |
| Analizada | Media (4.8) | 0.36% | — | Statamic | 21/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by… | |
| Analizada | Alta (8.7) | 0.45% | — | Statamic | 11/2/2026 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an… | |
| Analizada | Media (4.3) | 0.40% | — | Statamic | 11/2/2026 | 17/6/2026 | Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This… | |
| Aplazada | Media (6.5) | 0.23% | — | Statamic ALT RedirectAI | 10/10/2025 | 17/6/2026 | The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of… | |
| Aplazada | Alta (8.8) | 0.26% | — | Statamic CoreAI | 8/8/2025 | 17/6/2026 | The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via a JavaScript payload in a username during account registration. Reflected XSS can occur via the /users PATH_INFO. | |
| Aplazada | Media (5.3) | 0.58% | — | StatamicAI | 19/11/2024 | 17/6/2026 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured. The issue affects front-end forms with `assets` fields and other places where assets… | |
| Aplazada | Baja (1.8) | 0.14% | — | StatamicAILaravelAI | 30/5/2024 | 17/6/2026 | Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the following conditions: 1. Running Statamic… | |
| Modificada | Media (6.1) | 0.73% | — | Statamic | 1/2/2024 | 17/6/2026 | Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the control panel. Additionally, if the XSS is… | |
| Modificada | Media (6.1) | 0.70% | — | Statamic | 21/11/2023 | 17/6/2026 | Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an assets field, or within the control… | |
| Modificada | Alta (8.8) | 1.1% | — | Statamic | 14/11/2023 | 17/6/2026 | Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look like images may be uploaded regardless of mime type validation rules. This affects front-end forms using the "Forms" feature, and asset upload fields in the control… | |
| Modificada | Crítica (9.8) | 1.1% | — | Statamic | 10/11/2023 | 17/6/2026 | Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the… | |
| Modificada | Media (5.4) | 0.66% | — | Statamic | 5/7/2023 | 17/6/2026 | Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a… | |
| Modificada | Baja (3.7) | 1.0% | — | Statamic | 25/3/2022 | 17/6/2026 | Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not… | |
| Modificada | Crítica (9.8) | 1.7% | — | Statamic | 10/2/2022 | 17/6/2026 | A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product | |
| Modificada | Media (4.8) | 0.56% | — | Statamic | 19/12/2018 | 17/6/2026 | Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request. | |
| Modificada | Alta (8.8) | 0.87% | — | Statamic | 24/7/2017 | 17/6/2026 | Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc. |