Vulnerabilities (CVE)

Filtered by vendor Statamic Subscribe
Filtered by product Statamic
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47129 1 Statamic 1 Statamic 2023-11-17 N/A 9.8 CRITICAL
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.
CVE-2021-45364 1 Statamic 1 Statamic 2022-02-18 7.5 HIGH 9.8 CRITICAL
** DISPUTED ** A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product.