CVE-2026-25633
EUVD-2026-620111.02.2026, 21:16
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| statamic | statamic | 𝑥 < 5.73.6 |
| statamic | statamic | 6.0.0 ≤ 𝑥 < 6.2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration