CVE-2023-36828: Statamic
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue.
Affected products
- Statamic Statamic: before 4.10.0 (fixed in 4.10.0)
Published 2023-07-05. Last modified 2026-06-17.