The Statamic CMS Core Package
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-28426 New statamic/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.73.11 and 6.0.0-alpha.1 - 6.4.0. | 0.0.0 - 5.73.116.0.0-alpha.1 - 6.4.0 | High |
CVE-2026-28425 New statamic/cms is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 5.73.11 and 6.0.0-alpha.1 - 6.4.0. | 0.0.0 - 5.73.116.0.0-alpha.1 - 6.4.0 | High |
CVE-2026-28424 New statamic/cms is vulnerable to Missing Authorization in versions 0.0.0 - 5.73.11 and 6.0.0-alpha.1 - 6.4.0. | 0.0.0 - 5.73.116.0.0-alpha.1 - 6.4.0 | Medium |
CVE-2026-28423 New statamic/cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 5.73.11 and 6.0.0-alpha.1 - 6.4.0. | 0.0.0 - 5.73.116.0.0-alpha.1 - 6.4.0 | Medium |
CVE-2026-27939 New statamic/cms is vulnerable to Improper Authentication in versions 6.0.0 - 6.4.0. | 6.0.0 - 6.4.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.0 | — | — |
league/glide Version ^3.0 | — | — |
spatie/blink Version ^1.3 | — | — |
symfony/lock Version ^7.0.3 | — | — |
symfony/yaml Version ^7.0.3 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant