statamic/cms Security Advisories for v6.23.0 (6)
-
[MEDIUM] Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
PKSA-h7t4-kgpy-prgj CVE-2026-71435 GHSA-vx89-p3j7-8xqc
Affected version: >=6.0.0,<6.24.2|<5.74.3
Reported by:
GitHub -
[MEDIUM] Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
PKSA-htv4-42tq-8d9c CVE-2026-71434 GHSA-qhr7-v3xp-vw9m
Affected version: >=6.0.0,<6.24.2|<5.74.3
Reported by:
GitHub -
[MEDIUM] Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
PKSA-yprw-4kcc-73cg CVE-2026-64662 GHSA-qh8c-7588-qfrv
Affected version: >=6.0.0,<6.24.0|<5.74.1
Reported by:
GitHub -
[MEDIUM] Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
PKSA-p8hp-2yrt-f2d6 CVE-2026-64663 GHSA-j2vp-f2pv-5rj4
Affected version: >=6.0.0,<6.24.0|<5.74.1
Reported by:
GitHub -
[HIGH] Statamic: Account takeover via OAuth email matching without email-verification check
PKSA-vbqf-w9v5-8bfs CVE-2026-64665 GHSA-93qh-5269-9wcf
Affected version: >=6.0.0,<6.24.0|<5.74.1
Reported by:
GitHub -
[MEDIUM] Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
PKSA-691k-v8bf-zdg7 CVE-2026-64664 GHSA-225x-3jhx-wh4q
Affected version: >=6.0.0,<6.24.0|<5.74.1
Reported by:
GitHub