LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32612

statamic · statamic

Published
CVSS5.4
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. This has been fixed in 6.6.2.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32612

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32612.