---
id: CVE-2025-64112
title: Statmatic is a Laravel and Git powered content management system (CMS)
summary: >-
  Statmatic is a Laravel and Git powered content management system (CMS). Stored
  XSS vulnerabilities in Collections and Taxonomies allow authenticated users
  with content creation permissions to inject malicious JavaScript that executes
  whe…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2025-10-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64112'
references:
  - url: >-
      https://github.com/statamic/cms/commit/e513751f433679ce698606e20c554a0c839987c1
    label: security-advisories@github.com
  - url: 'https://github.com/statamic/cms/security/advisories/GHSA-g59r-24g3-h7cm'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00305
epssPercentile: 0.21029
ingestedAt: '2026-09-30T23:29:32.459Z'
---

## Overview

Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
