PT-2026-53028 · Git+2 · Cms+1

CVE-2026-54243

·

Published

2026-06-26

·

Updated

2026-07-20

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 5.73.24 Statamic versions prior to 6.20.1
Description Form submission values in src/Forms/Exporters/CsvExporter.php are not neutralized for spreadsheet formula characters during CSV export. An unauthenticated front-end visitor can provide a value starting with formula trigger characters such as =, +, -, or @. When a Control Panel user opens the exported file in a spreadsheet application, these values may be interpreted as live formulas. This issue affects the spreadsheet application used to view the export rather than the server or the application itself.
Recommendations Update to version 5.73.24. Update to version 6.20.1.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54243
GHSA-H77M-QRJ7-JXCW

Affected Products

Cms
Statamic Cms