statamic/cms Security Advisories for v5.6.0 (3)
- 
                        [HIGH] Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side ValidationPKSA-mmp9-wb2h-d8gy CVE-2025-64112 GHSA-g59r-24g3-h7cm Affected version: <=5.22.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Statamic CMS has a Path Traversal in Asset UploadPKSA-8gf5-xvpy-gbms CVE-2024-52600 GHSA-p7f6-8mcm-fwv3 Affected version: <=5.16.0 Reported by: 
 GitHub
- 
                        [LOW] Password confirmation stored in plain text via registration form in statamic/cmsPKSA-t5bn-h473-kjrn CVE-2024-36119 GHSA-qvpj-w7xj-r6w9 Affected version: >=5.3.0,<5.6.2 Reported by: 
 GitHub