The Statamic CMS Core Package
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-33887 statamic/cms is vulnerable to Missing Authorization in versions 0.0.0 - 5.73.16 and 6.0.0-alpha.1 - 6.7.2. | 0.0.0 - 5.73.166.0.0-alpha.1 - 6.7.2 | Medium |
CVE-2026-33886 statamic/cms is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.73.12 - 5.73.16 and 6.5.0 - 6.7.2. | 5.73.12 - 5.73.166.5.0 - 6.7.2 | Medium |
CVE-2026-33885 statamic/cms is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 5.73.16 and 6.0.0.alpha.1 - 6.7.2. | 0.0.0 - 5.73.166.0.0.alpha.1 - 6.7.2 | Medium |
CVE-2026-33884 statamic/cms is vulnerable to Incorrect Authorization in versions 0.0.0 - 5.73.16 and 6.0.0-alpha.1 - 6.7.2. | 0.0.0 - 5.73.166.0.0-alpha.1 - 6.7.2 | Medium |
CVE-2026-33883 statamic/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.73.16 and 6.0.0-alpha.1 - 6.7.2. | 0.0.0 - 5.73.166.0.0-alpha.1 - 6.7.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.0 | — | — |
league/glide Version ^3.0 | — | — |
spatie/blink Version ^1.3 | — | — |
symfony/lock Version ^7.0.3 || ^8.0 | — | — |
symfony/yaml Version ^7.0.3 || ^8.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant