Jason Varga
14 exploits
Active since Jul 2023
Statamic < 4.10.0 - Stored Cross-Site Scripting via Malicious SVG Upload
CVSS 5.5
Statamic < 3.4.13 and 4.0.0-4.33.0 - Unrestricted Upload of File with Dangerous Type via Front-End Forms
CVSS 8.3
Statamic < 3.4.13 and 4.0.0-4.33.0 - Unrestricted Upload of File with Dangerous Type via Front-End Forms
CVSS 8.3
Statamic CMS < 5.17.0 - Path Traversal via Crafted Filename Upload
CVSS 5.3
Statamic CMS < 5.17.0 - Path Traversal via Crafted Filename Upload
CVSS 5.3
Statmatic <6.3.3/5.73.10 - Auth Bypass
CVSS 9.3
Statmatic <=5.73.8/6.0.0-6.3.1 - Stored XSS
CVSS 8.1
Statmatic <6.3.3/5.73.10 - Auth Bypass
CVSS 9.3
Statmatic 6.0.0-6.3.9 - Privilege Escalation
CVSS 8.8
Statmatic <6.3.3/5.73.10 - Auth Bypass
CVSS 9.3
Statmatic <=5.73.8/6.0.0-6.3.1 - Stored XSS
CVSS 8.1
Statamic < 3.4.14 and 4.0.0-4.34.0 - Unrestricted Upload of File with Dangerous Type
CVSS 8.8
Statamic CMS < 5.17.0 - Path Traversal via Crafted Filename Upload
CVSS 5.3
Statamic CMS 6.0.0-6.2.2 - Authenticated Stored Cross-Site Scripting in Content Titles
CVSS 8.7