CVE-2026-33172Patch(statamic / statamic)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch statamic statamic systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that executes when the asset is viewed. This has been fixed in 5.73.14 and 6.7.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 103-2003-21
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
Patch2
2026-03-211
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33172 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows a… https://www.cve.org/CVERecord?id=CVE-2026-33172

    Post summary

    The excerpt announces a stored XSS vulnerability in Statamic before versions 5.73.14/6.7.0, noting that those releases patch the flaw, and references the CVE record.

    00000145
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-33172 - High Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with a... https://www.thehackerwire.com/vulnerability/CVE-2026-33172/ https://t.co/2AYvGLHqQu

    Post summary

    The post announces a stored XSS vulnerability in Statamic’s SVG asset reupload feature, affecting versions before 5.73.14 and 6.7.0, and notes that updating to those versions resolves the issue.

    0000040
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33172: HIGH] Cyber security alert: Statamic users, secure your site! Update to versions 5.73.14 or 6.7.0 to patch a stored XSS vulnerability in SVG asset reuploads. #cybersecurity#cve,CVE-2026-33172,#cybersecurity https://cvefind.com/CVE-2026-33172

    Post summary

    The advisory informs Statamic users of a stored XSS flaw in SVG asset reuploads and directs them to upgrade to patched versions 5.73.14 or 6.7.0.

    0000056
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more