{"id":"CVE-2025-64112","aliases":["GHSA-g59r-24g3-h7cm"],"url":"https://o3.security/vulnerability/CVE-2025-64112","summary":"Statmatic vulnerable to Stored Cross-Site Scripting","details":"### Impact\n\nStored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.\n\nThis affects:\n\n- Control panel users with permission to create or edit Collections and Taxonomies\n- Versions up to and including 5.22.0\n\nThe vulnerability can be exploited to:\n\n- Change a super admin's password (versions ≤ 5.21.0)\n- Change a super admin's email address to initiate password reset (version 5.22.0)\n- Gain unauthorized access to superadmin accounts\n\nThe attack requires:\n\n- An authenticated user with control panel and content creation permissions\n- A super admin to view the compromised content\n\n### Patches\n\nThis has been fixed in 5.22.1.\n\n### Credits\n\nStatamic thanks [Wojtek Chwala](https://github.com/wojtekchwala) for responsibly reporting the identified issues and working with us as we addressed them.","published":"2025-10-30T17:47:01.280Z","modified":"2026-08-12T03:51:19.069043900Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00285,"percentile":0.20722,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"statamic/cms","fixedVersion":"5.22.1"}],"fix":{"url":"https://github.com/statamic/cms/commit/e513751f433679ce698606e20c554a0c839987c1","label":"statamic/cms@e513751"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64112.json"},{"type":"ADVISORY","url":"https://github.com/statamic/cms/security/advisories/GHSA-g59r-24g3-h7cm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64112"},{"type":"FIX","url":"https://github.com/statamic/cms/commit/e513751f433679ce698606e20c554a0c839987c1"},{"type":"PACKAGE","url":"https://github.com/statamic/cms"},{"type":"WEB","url":"https://github.com/statamic/cms/releases/tag/v5.22.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.069043900Z"}}