# GHSA-8r7r-f4gm-wcpq: Statamic affected by privilege escalation via stored cross-site scripting

**Severity:** HIGH | **CVSS:** 8.1 | **Source:** ghsa

## Description

## Impact

Stored XSS vulnerability in `html` fieldtypes allow authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.

## Patches

This has been fixed in 6.3.2 and 5.73.9.

## CVSS

- **Score:** 8.1
- **Vector:** `CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N`

## Weakness

- [CWE-79](https://cwe.mitre.org/data/definitions/79.html)

## Affected Packages

### statamic/cms (composer)
- **Vulnerable:** `>= 6.0.0-alpha.1, < 6.3.2`
- **Patched:** `6.3.2`

### statamic/cms (composer)
- **Vulnerable:** `< 5.73.9`
- **Patched:** `5.73.9`

## References

- https://github.com/statamic/cms/security/advisories/GHSA-8r7r-f4gm-wcpq
- https://github.com/statamic/cms/commit/11ae40e62edd3da044d37ebf264757a09cc2347b
- https://github.com/statamic/cms/commit/6c270dacc2be02bfc2eee500766f3309f59d47b3
- https://github.com/advisories/GHSA-8r7r-f4gm-wcpq

---

**Source:** https://github.com/advisories/GHSA-8r7r-f4gm-wcpq
**Published:** 2026-02-19
**Ingested:** 2026-02-20 14:43:38 UTC

## Reproduction Steps

_To be determined by the reproduction agent._
