Stored XSS Vulnerability in Statamic CMS Affecting Authenticated Users
CVE-2026-28426

8.7HIGH

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
27 February 2026

What is CVE-2026-28426?

Statamic, a Laravel and Git based content management system, is prone to a stored XSS vulnerability in svg and icon components. This security flaw enables authenticated users with the right permissions to inject malicious JavaScript into the system. The injected scripts execute when the content is accessed by users with higher privileges, potentially leading to unauthorized actions and data exposure. The vulnerability has been addressed in versions 5.73.11 and 6.4.0, emphasizing the necessity for users to update to these versions to maintain system integrity.

Affected Version(s)

cms < 5.73.11 < 5.73.11

cms >= 6.0.0, < 6.4.0 < 6.0.0, 6.4.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.