CVE-2026-25633: Statamic
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.
Affected products
- Statamic Statamic: before 5.73.6 (fixed in 5.73.6); from 6.0.0, before 6.2.5 (fixed in 6.2.5)
Published 2026-02-11. Last modified 2026-06-17.