Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
|  Github GHSA | GHSA-g59r-24g3-h7cm | Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 30 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 30 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1. | |
| Title | Statmatic vulnerable to Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-30T17:58:06.993Z
Reserved: 2025-10-27T15:26:14.127Z
Link: CVE-2025-64112
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-30T17:58:01.973Z
 NVD
                        NVD
                    Status : Received
Published: 2025-10-30T18:15:33.183
Modified: 2025-10-30T18:15:33.183
Link: CVE-2025-64112
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.