Binary.ph@BinaryPhDisclosure
The post announces a new vulnerability (CVE-2026-28426) involving stored XSS and Antlers template injection in the Statamic Control Panel.
PulsePatch.io@pulsepatchioPatch
Statamic CMS is affected by CVE-2026-28426, a stored XSS that enables privilege escalation. Users should update statamic/cms to the latest version to mitigate the risk.
CVE@CVEnewPatch
CVE-2026-28426 is a stored XSS flaw in Statmatic CMS affecting SVG and icon components, fixed in versions 5.73.11 and 6.4.0.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
A new CVE (CVE-2026-28426) affecting Statamic is disclosed, highlighting a stored XSS vulnerability that can lead to privilege escalation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a stored XSS vulnerability in Statmatic CMS versions prior to 5.73.11 and 6.4.0, providing technical details but no evidence of exploitation or fixes.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces a high‑severity stored XSS vulnerability (CVE‑2026‑28426) in Statmatic CMS, affecting versions before 5.73.11 and 6.4.0, with no PoC, exploit tool, or active exploitation mentioned.
CVEFind.com@CveFindComPatch
The post announces a critical security update for Statmatic CMS to fix stored XSS vulnerabilities and urges users to update their installations.