Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-64112

Опубликовано: 30 окт. 2025
Источник: nvd
CVSS3: 8
EPSS Низкий

Описание

Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This vulnerability is fixed in 5.22.1.

EPSS

Процентиль: 14%
0.00046
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
github
3 месяца назад

Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation

EPSS

Процентиль: 14%
0.00046
Низкий

8 High

CVSS3

Дефекты

CWE-79