Stored XSS Vulnerability in Statamic Content Management System
CVE-2026-32612

5.4MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
12 March 2026

What is CVE-2026-32612?

The Statamic Content Management System, which leverages Laravel and Git, contains a stored XSS vulnerability that affects versions prior to 6.6.2. This vulnerability enables authenticated users with control panel access to inject malicious JavaScript code into the color mode preference setting. This malicious script can be executed when a higher-privileged user impersonates the identity of the affected user, potentially leading to unauthorized actions or data breaches. The issue has been addressed in version 6.6.2, emphasizing the importance of keeping software up to date to ensure security.

Affected Version(s)

cms >= 6.0.0, < 6.6.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.