{"id":"GHSA-ff9r-ww9c-43x8","summary":"Statamic CMS vulnerable to privilege escalation via stored cross-site scripting","details":"### Impact\nStored XSS vulnerability in content titles allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.\n\nMalicious user must have an account with control panel access and content creation permissions.\n\nThis vulnerability can be exploited to allow super admin accounts to be created.\n\n### Patches\nThis has been fixed in 6.2.3.","aliases":["CVE-2026-25759"],"modified":"2026-02-11T23:48:56.160099Z","published":"2026-02-11T18:17:58Z","database_specific":{"nvd_published_at":"2026-02-11T21:16:19Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-02-11T18:17:58Z"},"references":[{"type":"WEB","url":"https://github.com/statamic/cms/security/advisories/GHSA-ff9r-ww9c-43x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25759"},{"type":"WEB","url":"https://github.com/statamic/cms/commit/6ed4f65f3387686d6dbd816e9b4f18a8d9736ff6"},{"type":"PACKAGE","url":"https://github.com/statamic/cms"},{"type":"WEB","url":"https://github.com/statamic/cms/releases/tag/v6.2.3"}],"affected":[{"package":{"name":"statamic/cms","ecosystem":"Packagist","purl":"pkg:composer/statamic/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.2.3"}]}],"versions":["v6.0.0","v6.1.0","v6.2.0","v6.2.1","v6.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-ff9r-ww9c-43x8/GHSA-ff9r-ww9c-43x8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}