Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY43 SECURITY RECORDS

statamic

cms

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Statamic. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-71435 6 Aug 2026 < 5.74.3; >= 6.0.0, < 6.24.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71434 6 Aug 2026 < 5.74.3; >= 6.0.0, < 6.24.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-64662 6 Aug 2026 < 5.74.1; >= 6.0.0, < 6.24.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-64663 6 Aug 2026 < 5.74.1; >= 6.0.0, < 6.24.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-64665 6 Aug 2026 < 5.74.1; >= 6.0.0, < 6.24.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-64664 6 Aug 2026 >= 6.0.0, < 6.24.0; < 5.74.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-71293 5 Aug 2026 ≤ 6.23.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-54243 17 Jul 2026 < 5.73.24; >= 6.0.0, < 6.20.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-54242 17 Jul 2026 < 5.73.24; >= 6.0.0, < 6.20.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-54244 17 Jul 2026 < 5.74.0; >= 6.0.0, < 6.20.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-49288 19 Jun 2026 < 5.73.23; >= 6.0.0, < 6.20.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-49287 19 Jun 2026 < 5.73.23; >= 6.0.0, < 6.20.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-45660 29 May 2026 < 5.73.22; >= 6.0.0-alpha.1, < 6.18.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-44306 12 May 2026 < 5.73.21; >= 6.0.0, < 6.15.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-41175 22 Apr 2026 < 5.73.20; >= 6.0.0-alpha.1, < 6.13.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33887 27 Mar 2026 < 5.73.16; >= 6.0.0-alpha.1, < 6.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33886 27 Mar 2026 >= 5.73.12, < 5.73.16; >= 6.0.0.alpha.1, < 6.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33885 27 Mar 2026 < 5.73.16; >= 6.0.0.alpha.1, < 6.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33884 27 Mar 2026 < 5.73.16; >= 6.0.0-alpha.1, < 6.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33883 27 Mar 2026 < 5.73.16; >= 6.0.0-alpha.1, < 6.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33882 27 Mar 2026 < 5.73.16; >= 6.0.0-alpha.1, < 6.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33177 20 Mar 2026 >= 6.0.0-alpha.1, < 6.7.0; < 5.73.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33172 20 Mar 2026 >= 6.0.0-alpha.1, < 6.7.0; < 5.73.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-33171 20 Mar 2026 >= 6.0.0-alpha.1, < 6.7.0; < 5.73.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-32612 12 Mar 2026 >= 6.0.0, < 6.6.2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-28426 27 Feb 2026 < 5.73.11; >= 6.0.0, < 6.4.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-28425 27 Feb 2026 < 5.73.16; >= 6.0.0, < 6.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-28424 27 Feb 2026 < 5.73.11; >= 6.0.0, < 6.4.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-28423 27 Feb 2026 < 5.73.11; >= 6.0.0, < 6.4.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-27939 27 Feb 2026 >= 6.0.0, < 6.4.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-27593 24 Feb 2026 < 5.73.10; >= 6.0.0-alpha.1, < 6.3.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-27196 21 Feb 2026 >= 6.0.0-alpha.1, < 6.3.2; < 5.73.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-25759 11 Feb 2026 >= 6.0.0, < 6.2.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-25633 11 Feb 2026 < 5.73.6; >= 6.0.0-alpha.1, < 6.2.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-64112 30 Oct 2025 cms: < 5.22.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-52600 19 Nov 2024 < 5.17.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-36119 30 May 2024 >= 5.3.0, < 5.6.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-24570 1 Feb 2024 < 3.4.17; >= 4.0.0, < 4.46.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-48701 21 Nov 2023 < 3.4.15 ; >= 4.0.0, < 4.36.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-48217 14 Nov 2023 >= 4.0.0, < 4.34.0; < 3.4.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-47129 10 Nov 2023 < 3.4.13; >= 4.0.0, < 4.33.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-36828 5 Jul 2023 < 4.10.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-24784 25 Mar 2022 < 3.2.39; < 3.3.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.