CVE security advisories and vulnerability history for cms by statamic.
32
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
2
Public exploits
With known exploit
6.5
Avg CVSS
2022–2026
Last updated
Overview
statamic cms has 32 published CVE records since 2022, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 2 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting statamic cms, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of statamic cms's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High12
Medium16
Low2
1 additional CVE has no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of statamic cms's CVEs are currently listed in CISA's KEV catalog.
Public exploits
2
2 of statamic cms's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every statamic cms version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about statamic cms vulnerabilities.
How many CVEs does statamic cms have?
statamic cms has 32 published CVE records since 2022.
How many statamic cms CVEs are in CISA KEV?
None of statamic cms's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for statamic cms vulnerabilities?
Yes — 2 of statamic cms's CVEs have a known public exploit.
Which versions of statamic cms are affected?
601 distinct statamic cms versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in statamic cms CVEs?
statamic cms's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-862 (Missing Authorization), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
How many critical statamic cms vulnerabilities are there?
statamic cms has 1 critical and 12 high-severity CVEs.
What is the average severity of statamic cms CVEs?
The average CVSS base score across statamic cms's scored CVEs is 6.5.