CVE-2026-28426: Statamic vulnerable to privilege escalation via stored cross-site scripting
Impact Stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.
Patches This has been fixed in 5.73.11 and 6.4.0.
Other sources
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This has been fixed in 5.73.11 and 6.4.0.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28426?
CVE-2026-28426 is a high-severity vulnerability due to its potential for privilege escalation via stored cross-site scripting.
How do I fix CVE-2026-28426?
To fix CVE-2026-28426, upgrade to Statamic version 5.73.11 or 6.4.0 or later.
Who is affected by CVE-2026-28426?
CVE-2026-28426 affects all versions of Statamic prior to 5.73.11 and 6.4.0 that utilize svg and icon components.
What type of vulnerability is CVE-2026-28426?
CVE-2026-28426 is classified as a stored cross-site scripting (XSS) vulnerability.
Can authenticated users exploit CVE-2026-28426?
Yes, authenticated users with appropriate permissions can exploit CVE-2026-28426 to escalate privileges.