CVE 8 HIGH

Statmatic vulnerable to Stored Cross-Site Scripting_CVE-2025-64112

8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Description

Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.

Basic Information

ID CVE-2025-64112
Source GitHub_M
Published Oct 30, 2025 at 17:47
Modified Oct 30, 2025 at 17:58

Affected Product

Vendor statamic
Product cms
Version < 5.22.1
Affected Versions statamic cms < 5.22.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.