GHSA-g59r-24g3-h7cm

    Dashboard / Vulnerabilities / GHSA-g59r-24g3-h7cm

    GHSA-g59r-24g3-h7cm

    Published: 30 Oct 2025Last Modified: 30 Oct 2025

    Summary: Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation

    Details: ### Impact Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This affects: - Control panel users with permission to create or edit Collections and Taxonomies - Versions up to and including 5.22.0 The vulnerability can be exploited to: - Change a super admin's password (versions ≤ 5.21.0) - Change a super admin's email address to initiate password reset (version 5.22.0) - Gain unauthorized access to superadmin accounts The attack requires: - An authenticated user with control panel and content creation permissions - A super admin to view the compromised content ### Patches This has been fixed in 5.22.1. ### Credits Statamic thanks [Wojtek Chwala](https://github.com/wojtekchwala) for responsibly reporting the identified issues and working with us as we addressed them.

    Affected packages

    Package

    Name: statamic/cms

    Purl: pkg:composer/statamic/cms

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.22.1

    Affected versions

    v3.0.0
    v3.0.0-beta.1
    v3.0.0-beta.10
    v3.0.0-beta.11
    v3.0.0-beta.12
    v3.0.0-beta.13
    v3.0.0-beta.14
    v3.0.0-beta.15
    v3.0.0-beta.16
    v3.0.0-beta.17
    v3.0.0-beta.18
    v3.0.0-beta.19
    v3.0.0-beta.2
    v3.0.0-beta.20
    v3.0.0-beta.21
    v3.0.0-beta.22
    v3.0.0-beta.23
    v3.0.0-beta.24
    v3.0.0-beta.25
    v3.0.0-beta.26
    v3.0.0-beta.27
    v3.0.0-beta.28
    v3.0.0-beta.29
    v3.0.0-beta.3
    v3.0.0-beta.30
    v3.0.0-beta.31
    v3.0.0-beta.32
    v3.0.0-beta.33
    v3.0.0-beta.34
    v3.0.0-beta.35
    v3.0.0-beta.36
    v3.0.0-beta.37
    v3.0.0-beta.38
    v3.0.0-beta.39
    v3.0.0-beta.4
    v3.0.0-beta.40
    v3.0.0-beta.41
    v3.0.0-beta.42
    v3.0.0-beta.43
    v3.0.0-beta.44
    v3.0.0-beta.45
    v3.0.0-beta.46
    v3.0.0-beta.5
    v3.0.0-beta.6
    v3.0.0-beta.7
    v3.0.0-beta.8
    v3.0.0-beta.9
    v3.0.1
    v3.0.10
    v3.0.11
    v3.0.12
    v3.0.13
    v3.0.14
    v3.0.15
    v3.0.16
    v3.0.17
    v3.0.18
    v3.0.19
    v3.0.2
    v3.0.20
    v3.0.21
    v3.0.22
    v3.0.23
    v3.0.24
    v3.0.25
    v3.0.26
    v3.0.27
    v3.0.28
    v3.0.29
    v3.0.3
    v3.0.30
    v3.0.31
    v3.0.32
    v3.0.33
    v3.0.34
    v3.0.35
    v3.0.35.1
    v3.0.36
    v3.0.36.1
    v3.0.37
    v3.0.38
    v3.0.39
    v3.0.4
    v3.0.40
    v3.0.41
    v3.0.42
    v3.0.43
    v3.0.44
    v3.0.45
    v3.0.46
    v3.0.47
    v3.0.48
    v3.0.49
    v3.0.5
    v3.0.6
    v3.0.7
    v3.0.8
    v3.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g59r-24g3-h7cm | CVE-DB