← Retour à la recherche de CVE

CVE-2026-33886

Statamic

Description

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.

CVSS 6.5EPSS 0.22399999999999998%Risque 0.66
Voir la source
Publication
2026-03-27 21:17:25
Versions concernées
>=5.7.12,<5.73.16,<6.7.2
Type
Core software
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N