Template Manipulation Vulnerability in Statamic CMS by Statamic
CVE-2026-64663
6.5MEDIUM
What is CVE-2026-64663?
Statamic, a content management system built on Laravel, has vulnerabilities in versions prior to 5.74.1 and 6.24.0. By manipulating user-supplied input integrated within Antlers templates, attackers could compromise content and assets on sites where untrusted user input is processed. This manipulation poses significant risks as exploitation can occur without authentication. Users are advised to upgrade to the patched versions for mitigation.
Affected Version(s)
cms < 5.74.1 < 5.74.1
cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0
