Stored XSS Vulnerability in Statamic Content Management System
CVE-2026-25759

8.7HIGH

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
11 February 2026

What is CVE-2026-25759?

In Statamic CMS versions prior to 6.2.3, a stored XSS vulnerability exists that enables authenticated users with content creation permissions to insert malicious JavaScript into content titles. When these titles are viewed by users with higher privileges, the injected code executes, potentially allowing for security breaches, including the creation of super admin accounts. This vulnerability has been rectified in version 6.2.3.

Affected Version(s)

cms >= 6.0.0, < 6.2.3

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.