CVE-2026-27196
Impact
Stored XSS vulnerability in html fieldtypes allow authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.
Patches
This has been fixed in 6.3.2 and 5.73.9.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/statamic/cms/security/advisories/GHSA-8r7r-f4gm-wcpq, https://nvd.nist.gov/vuln/detail/CVE-2026-27196, https://github.com/statamic/cms/commit/11ae40e62edd3da044d37ebf264757a09cc2347b, https://github.com/statamic/cms/commit/6c270dacc2be02bfc2eee500766f3309f59d47b3, https://github.com/statamic/cms
