Record summary

CVE-2026-64663 has a selected CVSS score of 6.5 (medium).

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 5.74.1affected
>= 6.0.0, < 6.24.0affected
GitHub AdvisoryBefore 5.74.1 · Fixed in 5.74.1affected
6.0.0 to < 6.24.0 · Fixed in 6.24.0affected

References

2