Package Health

statamic/cms

The Statamic CMS Core Package

Latest v6.14.0PackagistPackagist

100%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Vulnerabilities

TitleVersionsSeverity
CVE-2026-33887
statamic/cms is vulnerable to Missing Authorization in versions 0.0.0 - 5.73.16 and 6.0.0-alpha.1 - 6.7.2.
0.0.0 - 5.73.166.0.0-alpha.1 - 6.7.2
Medium
CVE-2026-33886
statamic/cms is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.73.12 - 5.73.16 and 6.5.0 - 6.7.2.
5.73.12 - 5.73.166.5.0 - 6.7.2
Medium
CVE-2026-33885
statamic/cms is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 5.73.16 and 6.0.0.alpha.1 - 6.7.2.
0.0.0 - 5.73.166.0.0.alpha.1 - 6.7.2
Medium
CVE-2026-33884
statamic/cms is vulnerable to Incorrect Authorization in versions 0.0.0 - 5.73.16 and 6.0.0-alpha.1 - 6.7.2.
0.0.0 - 5.73.166.0.0-alpha.1 - 6.7.2
Medium
CVE-2026-33883
statamic/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.73.16 and 6.0.0-alpha.1 - 6.7.2.
0.0.0 - 5.73.166.0.0-alpha.1 - 6.7.2
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
league/csv
Version ^9.0
league/glide
Version ^3.0
spatie/blink
Version ^1.3
symfony/lock
Version ^7.0.3 || ^8.0
symfony/yaml
Version ^7.0.3 || ^8.0

Weekly Downloads

Info

Last Published
3 days ago
Created
6 years ago