Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYSERVER APPLICATIONVERIFIED

Statamic

Statamic

Statamic is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Statamic is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

Lifecycle records

ReleaseBoundaryDate
3.4Support endsJuly 2024
4Support endsSeptember 2024
5Support endsDecember 2026
6Support endsDecember 2027

Official sources

VERIFIED

Statamic official lifecycle source

Checked automatically.

Extracted 4 lifecycle record(s), including 4 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

Fixed: 5.73.23, 6.20.0

Statmic CMS vulnerable to account takeover via XSS and password reset link

Fixed: 4.46.0, 3.4.17

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Fixed: 5.73.23, 6.20.0

Statamic CMS: Server-Side Request Forgery via Glide

Fixed: 5.73.22, 6.18.1

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Fixed: 5.73.24, 6.20.1

Statamic Vulnerable to CSV formula injection in form submission exports

Fixed: 6.20.1, 5.73.24

Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors

Fixed: 5.74.0, 6.20.3

Password confirmation stored in plain text via registration form in statamic/cms

Fixed: 5.6.2