← Vulnerability feed

Vulnerability record · CVE-2022-24784 · published 25 March 2022

CVE-2022-24784: Statamic information exposure vulnerability

Statamic · Statamic

Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.

3.7 CVSS 3.1 Low EPSS 1.0% · top 37.6% CWE-200 · Information exposureCWE-203 · Observable discrepancy
3.7CVSS 3.1 base score, v2 4.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24784 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47129Statamic unrestricted file upload vulnerabilityStatmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi…EPSS 1.1%9.8CVE-2021-45364Statamic vulnerabilityA Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an err…EPSS 1.7%8.8CVE-2026-27939Statamic improper authentication vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…EPSS 0.46%8.8CVE-2026-27593Statamic weak password recovery vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability…EPSS 0.55%8.8CVE-2023-48217Statamic code injection vulnerabilityStatamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…EPSS 1.1%8.8CVE-2017-11422Statamic incorrect permission assignment vulnerabilityStatamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods…EPSS 0.87%8.7CVE-2026-33172Statamic cross-site scripting vulnerabilityStatamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…EPSS 0.36%8.7CVE-2026-25759Statamic cross-site scripting vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allo…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2022-24784), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.