CVE-2026-28426Disclosure(statamic / statamic)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch statamic statamic systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This has been fixed in 5.73.11 and 6.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-28); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-02-27: 2Mentions · 2026-02-28: 4Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 2Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 4Technical Details · 2026-03-01: 102-2702-2803-01
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1Patch1
2026-02-284
Disclosure2Patch2
2026-03-011
Disclosure1
Full discourse7 posts
  • Binary.ph@BinaryPh
    Disclosure

    CVE-2026-28426: Chain Reaction Stored XSS and Antlers Template Injection in Statamic Control Panel https://binary.ph/2026/03/01/cve-2026-28426-chain-reaction-stored-xss-and-antlers-template-injection-in-statamic-control-panel

    Post summary

    The post announces a new vulnerability (CVE-2026-28426) involving stored XSS and Antlers template injection in the Statamic Control Panel.

    0000058
    14 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Statamic` CMS is vulnerable to privilege escalation via stored XSS (CVE-2026-28426). Update `statamic/cms` to fix. #Statamic #XSS #InfoSec https://www.pulsepatch.io/posts/cve-2026-28426-statamic-privilege-escalation-xss

    Post summary

    Statamic CMS is affected by CVE-2026-28426, a stored XSS that enables privilege escalation. Users should update statamic/cms to the latest version to mitigate the risk.

    0000060
    1 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-28426 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related componen… https://www.cve.org/CVERecord?id=CVE-2026-28426

    Post summary

    CVE-2026-28426 is a stored XSS flaw in Statmatic CMS affecting SVG and icon components, fixed in versions 5.73.11 and 6.4.0.

    0000098
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28426 - Statamic vulnerable to privilege escalation via stored cross-site scripting Intel Report: https://ift.tt/kzYVXDK

    Post summary

    A new CVE (CVE-2026-28426) affecting Statamic is disclosed, highlighting a stored XSS vulnerability that can lead to privilege escalation.

    0000014
    341 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28426 Stored XSS Vulnerability in Statmatic CMS Before Versions 5.73.11 and 6.4.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28426

    Post summary

    The text announces a stored XSS vulnerability in Statmatic CMS versions prior to 5.73.11 and 6.4.0, providing technical details but no evidence of exploitation or fixes.

    0000048
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28426 - High Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS vulnerability in svg and icon related components allow authenticated us... https://www.thehackerwire.com/vulnerability/CVE-2026-28426/ https://t.co/LjBuXlBNld

    Post summary

    The tweet announces a high‑severity stored XSS vulnerability (CVE‑2026‑28426) in Statmatic CMS, affecting versions before 5.73.11 and 6.4.0, with no PoC, exploit tool, or active exploitation mentioned.

    0000065
    119 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28426: HIGH] Critical security update for Statmatic CMS! Versions 5.73.11 and 6.4.0 address stored XSS vulnerabilities. Update now to safeguard against potential cyber threats. #cybersecurity#cve,CVE-2026-28426,#cybersecurity https://cvefind.com/CVE-2026-28426

    Post summary

    The post announces a critical security update for Statmatic CMS to fix stored XSS vulnerabilities and urges users to update their installations.

    0000059
    585 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more