CVE-2026-28425 | Statamic CMS up to 5.73.10/6.3.x code injection (GHSA-cpv7-q2wx-m8rw / EUVD-2026-9094)
A vulnerability has been found in Statamic CMS up to 5.73.10/6.3.x and classified as critical. This issue affects some unknown processing. This manipulation causes code injection.
This vulnerability appears as CVE-2026-28425. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.