Unsafe Reflection Affecting statamic/cms package, versions <5.73.23>=6.0.0-alpha.1, <6.20.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-STATAMICCMS-17426329
  • published23 Jun 2026
  • disclosed19 Jun 2026
  • creditEeshwar Dronavalli

Introduced: 19 Jun 2026

NewCVE-2026-49287  (opens in a new tab)
CWE-470  (opens in a new tab)

How to fix?

Upgrade statamic/cms to version 5.73.23, 6.20.0 or higher.

Overview

Affected versions of this package are vulnerable to Unsafe Reflection via the sort parameter in collection sorting. An attacker can cause loss of content and assets by manipulating input passed from a front-end template into the sorting process. This is only exploitable if a template is explicitly configured to sort by a visitor-controlled value, which they are not by default.

Note: This is a bypass of the fix for the vulnerability described in CVE-2026-41175.

CVSS Base Scores

version 4.0
version 3.1