CVE-2026-54243
Last modified
CVE-2026-54243 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value beginning with a formula trigger character, such as =, +, -, or @, could be interpreted as a live formula when a Control Panel user opens the export in a spreadsheet application. Form submissions can come from unauthenticated front-end visitors, so the malicious value can be supplied by an anonymous user and is later triggered by an editor opening the export. This issue is fixed in versions 5.73.24 and 6.20.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| statamic | cms | < 5.73.24; >= 6.0.0, < 6.20.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54243?
How severe is CVE-2026-54243?
How do I fix CVE-2026-54243?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54236vLLM is an inference and serving engine for large language m…5.3
- CVE-2026-54237Wavelog is web-based amateur radio logging software. From 1.…9.3
- CVE-2026-54239Faust.js is a headless WordPress toolkit. Prior to 1.8.11, t…8.8
- CVE-2026-54240libde265 is an open source implementation of the h.265 video…7.4
- CVE-2026-54241libde265 is an open source implementation of the h.265 video…7.4
- CVE-2026-54242Statamic is a Laravel and Git powered content management sys…4.9
- CVE-2026-54244Statamic is a Laravel and Git powered content management sys…3.5
- CVE-2026-54245Fleet is an open-source device management platform built on …7.6
- CVE-2026-54246Skipper is an HTTP router and reverse proxy for service comp…5.7
- CVE-2026-54247Skipper is an HTTP router and reverse proxy for service comp…4.3
- CVE-2026-54248Doco-CD is a GitOps continuous delivery tool that automatica…6.5
- CVE-2026-54249Pydantic AI is a Python agent framework for building Generat…6.8
Are you affected by CVE-2026-54243?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
