Statamic 6 security: being on version 6 isn't enough
Statamic 6 security comes down to the release you're on, not the version number. Below 6.24.2 (released on 8 July 2026), a site is missing at least two published security fixes. The latest release has every fix Statamic has released, and keeping up with updates is the best protection you have.
The cut-off keeps moving, too. New vulnerabilities are found all the time, and that's one of the main reasons Statamic releases new versions so often. There were five releases of Statamic 6 in September alone. If your business depends on your website, updating once, or now and then, isn't enough anymore.
Below Statamic 6.24.2
If your site is on Statamic 6 and running anything below 6.24.2, it has at least two known vulnerabilities: the two that 6.24.2 fixed, both rated moderate.
moderateFront-end forms ignored the file types allowed on their upload fields. A visitor could upload types you'd meant to block, though Statamic still blocked dangerous ones such as .php. (CVE-2026-71434)moderateThe default form notification email printed what people typed as raw HTML, the code web pages are made of. Anyone submitting a form could add their own HTML to the email your team receives. (CVE-2026-71435)
Sites further behind have more, and some are more serious. One rated high let an attacker sign in as an existing user, even a super admin, without their password. It only affected sites that let people sign in with an outside account (OAuth) from a provider that doesn't verify email addresses. Statamic 6 fixed it in 6.24.0. (CVE-2026-64665)
Why the gap matters
When a security issue is found and fixed in open source software, the project usually publishes a security advisory. Statamic publishes its advisories on GitHub, and they're listed in public databases such as the GitHub Advisory Database, the CVE list and the Open Source Vulnerabilities database (OSV).
Issues are graded low, moderate, high or critical. If you have a high or critical vulnerability it's best to get that patched sooner rather than later.
The gap between a vulnerability being made public and it being exploited has been getting shorter and shorter. In a Google Cloud blog post, How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends, Security firm, Mandiant found that the average time from a fix coming out to the flaw being exploited fell from 63 days in 2018 and 2019 to five days in 2023. Its latest report, M-Trends 2026: Data, Insights, and Strategies From the Frontlines, puts it at minus seven days, meaning attacks routinely start before a fix is even released.
The average time from a fix coming out to the flaw being exploited fell from 63 days in 2018 and 2019 to five days in 2023.
Artificial intelligence (AI) tools are speeding this up. Two researchers built a system that turns a published advisory into a working exploit in 10 to 15 minutes, for about $1 each. It relies on the code and the fix being public, as they are for all open source software.
Why the newest release is the better target
Since May 2026, Statamic has usually shipped a security fix about a month before publishing the advisory for it. On 1 July, for example, 5.74.1 and 6.24.0 fixed four issues that weren't announced until 6 August. One of them was a high-severity account takeover.
So the newest release can contain fixes that no list shows yet. A site that updates regularly has those fixes before anyone knows they were needed. A site that waits for an announcement gets them a month late.
How to check your Statamic version
There are two ways to find it.
In the Control Panel (CP), open Tools > Updates. Statamic's entry there shows the release you're running as its Current Version.
On the server, run
php please --versionin the site's folder. It prints a line such asStatamic 6.35.0.
Where these numbers come from
Everything here comes from public sources, so you can check it yourself. OSV lists every published Statamic advisory and the releases it affects. Packagist, the public registry Statamic is installed from, shows how often each version is downloaded. I pulled both on 2 October 2026. None of it comes from Sentinel, which doesn't send any data back to me.
In the last full week of that data, 21 to 27 September, 13% of Statamic 6 installs were on a release below 6.24.2.
Read that as a rough guide. Packagist counts installs and deploys, not websites, and a site nobody touches downloads nothing, so it isn't counted at all. Being affected also isn't the same as being hacked. Many of these advisories need a CP login, or a feature such as forms, before anyone can use them.
What to do next
If you're not sure where your site stands, install Sentinel. It's a free Statamic addon that checks your versions against OSV and other public sources, then emails you a status report, once or on a daily, weekly or monthly schedule. Unlike this post, it stays current when the next advisory comes out.
Sentinel tells you what needs doing. It doesn't do it for you. If you'd rather hand that part over, my monthly website maintenance covers Statamic updates, the packages your site depends on, and a report after each update showing what changed.
Still on Statamic 5? Its security fixes stop in December 2026, so start there.
You might also like...
- Statamic 5 security countdown: fixes stop in December 2026
- Darkroom: a Statamic AI image generator for Nano Banana
- Tracer 2.0: my Statamic UTM builder gets site-wide settings
- Sentinel 2.3.0: faster scans for my Statamic security addon
- Warming Statamic static cache behind basic auth
- Over 250 installs on: Sentinel and CMS security for Statamic
- Statamic background recache smooths out bulk cache invalidations
- What a software supply chain attack means for your Statamic website
- A 7-day cooldown against npm supply-chain attacks
- Browser console errors: when the noise hides the signal