Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w878-f8c6-7r63 | Statamic's missing authorization allows access to email addresses |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic statamic
|
|
| CPEs | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Statamic statamic
|
Mon, 02 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Fri, 27 Feb 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0. | |
| Title | Statamic's missing authorization allows access to email addresses | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-02T19:36:06.660Z
Reserved: 2026-02-27T15:54:05.136Z
Link: CVE-2026-28424
Updated: 2026-03-02T19:36:00.974Z
Status : Analyzed
Published: 2026-02-27T23:16:05.447
Modified: 2026-03-05T14:46:10.460
Link: CVE-2026-28424
No data.
OpenCVE Enrichment
Updated: 2026-03-02T12:04:30Z
Github GHSA