CVE-2026-28425 Details
Description
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the application, including access to sensitive configuration, modification or exfiltration of data, and potential impact on availability. Exploitation is only possible where Antlers runs on user-controlled content—for example, content fields with Antlers explicitly enabled (requiring permission to configure fields and to edit entries), built-in config that supports Antlers such as Forms email notification settings (requiring configuration permission), or third-party addons that add Antlers-enabled fields to entries (for example, the SEO Pro addon). In each case the attacker must have the relevant control panel permissions. This has been fixed in 5.73.16 and 6.7.2. Users of addons that depend on Statamic should ensure that after updating they are running a patched Statamic version.
A remote code execution vulnerability has been identified in Statamic CMS versions prior to 5.73.11 and 6.4.0. This issue affects authenticated control panel users who have access to Antlers-enabled inputs. Exploitation is possible in contexts where Antlers is applied to user-controlled content, such as specific content fields, certain built-in configuration options like Forms email notifications, or through third-party addons that introduce Antlers-enabled fields. The vulnerability allows for a complete compromise of the application, including unauthorized access to sensitive configuration data, manipulation or exfiltration of information, and potential disruptions to application availability.
Users can upgrade to Statamic versions 5.73.11 or 6.4.0 to address this vulnerability. Those using addons that depend on Statamic should ensure they are running a patched version after the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/statamic/cms/releases/tag/v5.73.11 | [email protected] | Release Notes |
| https://github.com/statamic/cms/releases/tag/v6.4.0 | [email protected] | Release Notes |
| https://github.com/statamic/cms/security/advisories/GHSA-cpv7-q2wx-m8rw | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| statamic statamic | < 5.73.11 >= 6.0.0, < 6.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |