The Statamic CMS Core Package
94%
Total Score
100
50
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-884281 statamic/cms is vulnerable to Unsafe Reflection in versions 0.0.1 - 5.74.3 and 6.0.0 - 6.27.1. | 0.0.1 - 5.74.36.0.0 - 6.27.1 | High |
AIKIDO-2026-845922 statamic/cms is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 5.74.3 and 6.0.0 - 6.27.1. | 0.0.1 - 5.74.36.0.0 - 6.27.1 | Medium |
CVE-2026-71435 statamic/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.74.3 and 6.0.0 - 6.24.2. | 0.0.0 - 5.74.36.0.0 - 6.24.2 | Medium |
CVE-2026-71434 statamic/cms is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.0 - 5.74.3 and 6.0.0 - 6.24.2. | 0.0.0 - 5.74.36.0.0 - 6.24.2 | Medium |
CVE-2026-71293 statamic/cms is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 6.0.0-alpha.1 - 6.30.0. | 6.0.0-alpha.1 - 6.30.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.1 | — | — |
league/glide Version ^3.0 || ^4.0 | — | — |
spatie/blink Version ^1.3 | — | — |
symfony/lock Version ^7.0.3 || ^8.0 | — | — |
symfony/yaml Version ^7.0.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.