PT-2026-53028 · Git+2 · Cms+1
CVE-2026-54243
·
Published
2026-06-26
·
Updated
2026-07-20
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Statamic versions prior to 5.73.24
Statamic versions prior to 6.20.1
Description
Form submission values in
src/Forms/Exporters/CsvExporter.php are not neutralized for spreadsheet formula characters during CSV export. An unauthenticated front-end visitor can provide a value starting with formula trigger characters such as =, +, -, or @. When a Control Panel user opens the exported file in a spreadsheet application, these values may be interpreted as live formulas. This issue affects the spreadsheet application used to view the export rather than the server or the application itself.Recommendations
Update to version 5.73.24.
Update to version 6.20.1.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cms
Statamic Cms