Template Manipulation Vulnerability in Statamic CMS by Statamic
CVE-2026-64663

6.5MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64663?

Statamic, a content management system built on Laravel, has vulnerabilities in versions prior to 5.74.1 and 6.24.0. By manipulating user-supplied input integrated within Antlers templates, attackers could compromise content and assets on sites where untrusted user input is processed. This manipulation poses significant risks as exploitation can occur without authentication. Users are advised to upgrade to the patched versions for mitigation.

Affected Version(s)

cms < 5.74.1 < 5.74.1

cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.