CVE-2026-28426

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This has been fixed in 5.73.11 and 6.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*

History

05 Mar 2026, 14:32

Type Values Removed Values Added
First Time Statamic statamic
Statamic
References () https://github.com/statamic/cms/releases/tag/v5.73.11 - () https://github.com/statamic/cms/releases/tag/v5.73.11 - Release Notes
References () https://github.com/statamic/cms/releases/tag/v6.4.0 - () https://github.com/statamic/cms/releases/tag/v6.4.0 - Release Notes
References () https://github.com/statamic/cms/security/advisories/GHSA-5vrj-wf7v-5wr7 - () https://github.com/statamic/cms/security/advisories/GHSA-5vrj-wf7v-5wr7 - Patch, Vendor Advisory
CPE cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
Summary
  • (es) Statmatic es un sistema de gestión de contenido (CMS) impulsado por Laravel y Git. Antes de las versiones 5.73.11 y 6.4.0, una vulnerabilidad de XSS almacenado en componentes relacionados con SVG e iconos permite a usuarios autenticados con los permisos adecuados inyectar JavaScript malicioso que se ejecuta cuando es visto por usuarios con mayores privilegios. Esto ha sido corregido en 5.73.11 y 6.4.0.

27 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 23:16

Updated : 2026-03-05 14:32


NVD link : CVE-2026-28426

Mitre link : CVE-2026-28426

CVE.ORG link : CVE-2026-28426


JSON object : View

Products Affected

statamic

  • statamic
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')