Security Advisory

CVE-2026-71435

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-06 19:37:54
Last updated 2026-08-06 19:37:54
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2.