CVE-2018-19598: Statamic

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

Affected products

Published 2018-12-19. Last modified 2026-06-17.