CVE-2026-64663
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.
| CWE | CWE-470 |
| Vendor | statamic |
| Product | cms |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for statamic cms
Be the first to know when new medium vulnerabilities affecting statamic cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Affected Versions
statamic / cms
< 5.74.1 >= 6.0.0, < 6.24.0