PT-2026-22422 · Statmatic · Statmatic

Dxleryt

·

Published

2026-02-27

·

Updated

2026-03-05

·

CVE-2026-28423

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Statmatic versions prior to 5.73.11 Statmatic versions prior to 6.4.0
Description Statmatic is a content management system. When Glide image manipulation is used in insecure mode, an unauthenticated user can exploit the image proxy to make the server send HTTP requests to arbitrary URLs. This can potentially allow access to internal services and cloud metadata endpoints reachable from the server.
Recommendations Update to version 5.73.11 or later. Update to version 6.4.0 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-28423
GHSA-CWPP-325Q-2CVP

Affected Products

Statmatic