The Statamic CMS Core Package
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-45660 statamic/cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 5.73.22 and 6.0.0-alpha.1 - 6.18.1. | 0.0.0 - 5.73.226.0.0-alpha.1 - 6.18.1 | Medium |
AIKIDO-2026-10749 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. statamic/cms is vulnerable to Insufficient Verification of Data Authenticity in versions 4.38.0 - 6.15.0. | 4.38.0 - 6.15.0 | Medium |
CVE-2026-44306 statamic/cms is vulnerable to Observable Response Discrepancy in versions 0.0.0 - 5.73.21 and 6.0.0 - 6.15.0. | 0.0.0 - 5.73.216.0.0 - 6.15.0 | Medium |
AIKIDO-2026-10616 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. statamic/cms is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 6.14.0. | 3.0.0 - 6.14.0 | Medium |
AIKIDO-2026-10615 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. statamic/cms is vulnerable to Observable Discrepancy in versions 0.0.1 - 6.14.0. | 0.0.1 - 6.14.0 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.1 | — | — |
league/glide Version ^3.0 | — | — |
spatie/blink Version ^1.3 | — | — |
symfony/lock Version ^7.0.3 || ^8.0 | — | — |
symfony/yaml Version ^7.0.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant