CVE-2026-28426
Impact
Stored XSS vulnerability in svg and icon related components allow authenticated users with appropriate permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.
Patches
This has been fixed in 5.73.11 and 6.4.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/statamic/cms/security/advisories/GHSA-5vrj-wf7v-5wr7, https://nvd.nist.gov/vuln/detail/CVE-2026-28426, https://github.com/statamic/cms, https://github.com/statamic/cms/releases/tag/v5.73.11, https://github.com/statamic/cms/releases/tag/v6.4.0
