statamic/cms Security Advisories (9)
- 
                        [MEDIUM] Statamic CMS has a Path Traversal in Asset UploadPKSA-8gf5-xvpy-gbms CVE-2024-52600 GHSA-p7f6-8mcm-fwv3 Affected version: <=5.16.0 Reported by: 
 GitHub
- 
                        [LOW] Password confirmation stored in plain text via registration form in statamic/cmsPKSA-t5bn-h473-kjrn CVE-2024-36119 GHSA-qvpj-w7xj-r6w9 Affected version: >=5.3.0,<5.6.2 Reported by: 
 GitHub
- 
                        [HIGH] Statmic CMS vulnerable to account takeover via XSS and password reset linkPKSA-8pw7-xndm-5j7f CVE-2024-24570 GHSA-vqxq-hvxw-9mv9 Affected version: <3.4.17|>=4.00,<4.46.0 Reported by: 
 GitHub
- 
                        [HIGH] Cross-site Scripting via uploaded assetsPKSA-jwp2-xxh9-t8xp CVE-2023-48701 GHSA-8jjh-j3c2-cjcv Affected version: >=4.0.0,<4.36.0|<3.4.15 Reported by: 
 GitHub
- 
                        [HIGH] Statamic CMS vulnerable to remote code execution via form uploadsPKSA-8hch-61s9-d7gd CVE-2023-48217 GHSA-2r53-9295-3m86 Affected version: <3.4.14|>=4.0.0,<4.34.0 Reported by: 
 GitHub
- 
                        [HIGH] Statamic CMS remote code execution via front-end form uploadsPKSA-tcb6-sf7c-j9gd CVE-2023-47129 GHSA-72hg-5wr5-rmfc Affected version: <3.4.13|>=4.0.0,<4.33.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Statamic's Antlers sanitizer cannot effectively sanitize malicious SVGPKSA-gfgd-dxd9-46qj CVE-2023-36828 GHSA-6r5g-cq4q-327g Affected version: <4.10.0 Reported by: 
 GitHub
- 
                        [HIGH] Statamic framework Incorrect Permission AssignmentPKSA-4tcv-4gx7-56hm CVE-2017-11422 GHSA-5m64-9hq5-5pf2 Affected version: <2.6.0 Reported by: 
 GitHub
- 
                        [LOW] Discoverability of user password hash in Statamic CMSPKSA-8nyw-p1dz-nqqq CVE-2022-24784 GHSA-qcgx-7p5f-hxvr Affected version: >=3.3.0,<3.3.2|<3.2.39 Reported by: 
 GitHub