CVE-2026-71435
MEDIUMStatamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Title source: cnaDescription
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/statamic/cms/security/advisories/GHSA-vx89-p3j7-8xqc
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/pull/14959
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/commit/4ad1335e818a67249d0617f0f167a1198fb96a2c
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/releases/tag/v5.74.3
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/releases/tag/v6.24.2
Scores
CVSS v3
6.1
EPSS
0.0019
EPSS Percentile
8.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (4)
statamic/cms
0 - 5.74.3Packagist
statamic/cms
6.0.0 - 6.24.2Packagist
statamic/cms
< 5.74.3
statamic/cms
>= 6.0.0, < 6.24.2
Published
Aug 06, 2026
Tracked Since
Aug 07, 2026