CVE-2026-71435

MEDIUM

Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template

Title source: cna
STIX 2.1

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2.

References (5)

Core 5

Scores

CVSS v3 6.1
EPSS 0.0019
EPSS Percentile 8.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
statamic/cms 0 - 5.74.3Packagist
statamic/cms 6.0.0 - 6.24.2Packagist
statamic/cms < 5.74.3
statamic/cms >= 6.0.0, < 6.24.2
Published Aug 06, 2026
Tracked Since Aug 07, 2026