← Vulnerability feed

Vulnerability record · CVE-2026-25759 · published 11 February 2026

CVE-2026-25759: Statamic cross-site scripting vulnerability

Statamic · Statamic

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an account with control panel access and content creation permissions. This vulnerability can be exploited to allow super admin accounts to be created. This has been fixed in 6.2.3.

8.7 CVSS 3.1 High EPSS 0.44% · top 64.1% CWE-79 · Cross-site scripting
8.7CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an account with control panel access and content creation permissions. This vulnerability can be exploited to allow super admin accounts to be created. This has been fixed in 6.2.3.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25759 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47129Statamic unrestricted file upload vulnerabilityStatmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi…EPSS 1.1%9.8CVE-2021-45364Statamic vulnerabilityA Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an err…EPSS 1.7%8.8CVE-2026-27939Statamic improper authentication vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…EPSS 0.46%8.8CVE-2026-27593Statamic weak password recovery vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability…EPSS 0.55%8.8CVE-2023-48217Statamic code injection vulnerabilityStatamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…EPSS 1.1%8.8CVE-2017-11422Statamic incorrect permission assignment vulnerabilityStatamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods…EPSS 0.87%8.7CVE-2026-33172Statamic cross-site scripting vulnerabilityStatamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…EPSS 0.36%8.6CVE-2026-28423Statamic server-side request forgery (ssrf) vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2026-25759), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.