8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Description
Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.
Basic Information
ID
CVE-2025-64112
Source
GitHub_M
Published
Oct 30, 2025 at 17:47
Modified
Oct 30, 2025 at 17:58
Affected Product
Vendor
statamic
Product
cms
Version
< 5.22.1
Affected Versions
statamic cms < 5.22.1