CVE-2026-33886
EUVD-2026-1683027.03.2026, 21:17
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| statamic | statamic | 5.73.12 ≤ 𝑥 < 5.73.16 |
| statamic | statamic | 6.5.0 ≤ 𝑥 < 6.7.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration