CVE-2026-49287
HIGHStatamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction
Title source: cnaDescription
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue in the query builder, but the same protection was not applied to in-memory collection sorting. Manipulating sort parameters could result in the loss of content and assets. This requires a front-end template that passes request input into a tag's sort parameter. It is not exploitable by default — a template would need to be explicitly set up to sort by a visitor-controlled value. This has been fixed in 5.73.23 and 6.20.0.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/statamic/cms/security/advisories/GHSA-m92m-r54r-x8r2
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/security/advisories/GHSA-4jjr-vmv7-wh4w
Scores
CVSS v3
7.4
EPSS
0.0027
EPSS Percentile
18.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-470
Status
published
Products (2)
statamic/cms
< 5.73.23
statamic/cms
>= 6.0.0, < 6.20.0
Published
Jun 19, 2026
Tracked Since
Jun 19, 2026