Junglewise Threat Intelligence

CVE-2026-25759: Statamic CMS vulnerable to privilege escalation via stored cross-site scripting

CVE-2026-25759 · Severity: low · CVSS 3.1 · Published 2026-02-11

Technologies: statamic/cms (Packagist). Vendors: Packagist.

Executive brief

Statamic CMS vulnerable to privilege escalation via stored cross-site scripting

Affected products

  • Packagist statamic/cms

Related threats