PT-2025-32359 · Unknown · Statamic Core

CVE-2020-9322

·

Published

2025-08-08

·

Updated

2025-08-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Statamic Core versions prior to 2.11.8
Description The /users endpoint is susceptible to cross-site scripting (XSS), potentially allowing an attacker to add an administrator user. Exploitation can occur through Cross-Site Request Forgery (CSRF). Stored XSS can be triggered by injecting a JavaScript payload within the username field during account registration. Reflected XSS can be triggered via the /users API endpoint.
Recommendations Update to Statamic Core version 2.11.8 or later. As a temporary workaround, restrict access to the /users API endpoint. Sanitize the username input field during account registration to prevent the injection of JavaScript payloads.

Fix

CSRF

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9322

Affected Products

Statamic Core