Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16 and 6.7.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8vwx-ccf6-5wg2 | Statamic's live preview token bypasses content protection for unrelated entries |
References
History
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16 and 6.7.2. | |
| Title | Statamic's live preview token bypasses content protection for unrelated entries | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T20:38:19.737Z
Reserved: 2026-03-24T15:10:05.681Z
Link: CVE-2026-33884
No data.
Status : Received
Published: 2026-03-27T21:17:25.183
Modified: 2026-03-27T21:17:25.183
Link: CVE-2026-33884
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA