The Statamic CMS Core Package
91%
Total Score
100
41
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-49287 statamic/cms is vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in versions 0.0.0 - 5.73.23 and 6.0.0 - 6.20.0. | 0.0.0 - 5.73.236.0.0 - 6.20.0 | High |
CVE-2026-49288 statamic/cms is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 5.73.23 and 6.0.0 - 6.20.0. | 0.0.0 - 5.73.236.0.0 - 6.20.0 | Medium |
CVE-2026-54244 statamic/cms is vulnerable to Incorrect Authorization in versions 0.0.0 - 5.74.0 and 6.0.0 - 6.20.3. | 0.0.0 - 5.74.06.0.0 - 6.20.3 | Low |
CVE-2026-54243 statamic/cms is vulnerable to Improper Neutralization of Formula Elements in a CSV File in versions 6.0.0 - 6.20.1 and 0.0.0 - 5.73.24. | 0.0.0 - 5.73.246.0.0 - 6.20.1 | Medium |
CVE-2026-54242 statamic/cms is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 5.73.24 and 6.0.0 - 6.20.1. | 0.0.0 - 5.73.246.0.0 - 6.20.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.1 | — | — |
league/glide Version ^3.0 || ^4.0 | — | — |
spatie/blink Version ^1.3 | — | — |
symfony/lock Version ^7.0.3 || ^8.0 | — | — |
symfony/yaml Version ^7.0.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant