CVE-2018-19598: Statamic
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.
Affected products
- Statamic Statamic: version 2.10.3 only
Published 2018-12-19. Last modified 2026-06-17.