PT-2026-22428 · Statmatic · Statmatic

Jasonvarga

·

Published

2026-02-27

·

Updated

2026-03-05

·

CVE-2026-28426

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Statmatic versions prior to 5.73.11 Statmatic versions prior to 6.4.0
Description Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, a stored cross-site scripting (XSS) issue exists in the svg and icon related components. This allows authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.
Recommendations Versions prior to 5.73.11 should be updated to version 5.73.11 or later. Versions prior to 6.4.0 should be updated to version 6.4.0 or later.

Exploit

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-28426
GHSA-5VRJ-WF7V-5WR7

Affected Products

Statmatic