CVE-2026-25759: Statmatic affected by privilege escalation via stored cross-site scripting
Impact Stored XSS vulnerability in content titles allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.
Malicious user must have an account with control panel access and content creation permissions.
This vulnerability can be exploited to allow super admin accounts to be created.
Patches This has been fixed in 6.2.3.
Other sources
Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an account with control panel access and content creation permissions. This vulnerability can be exploited to allow super admin accounts to be created. This has been fixed in 6.2.3.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25759?
CVE-2026-25759 is classified as a stored XSS vulnerability that can severely compromise the security of higher-privileged users.
How do I fix CVE-2026-25759?
To fix CVE-2026-25759, upgrade the statamic/cms package to version 6.2.3 or later.
Who is affected by CVE-2026-25759?
Authenticated users with content creation permissions in versions from 6.0.0 to 6.2.3 of statamic/cms are affected by CVE-2026-25759.
What kind of attack does CVE-2026-25759 allow?
CVE-2026-25759 allows malicious users to inject JavaScript that executes when viewed by higher-privileged users.
Can CVE-2026-25759 be exploited by non-authenticated users?
No, CVE-2026-25759 can only be exploited by authenticated users with control panel access and content creation permissions.