CVE-2026-71435: Statamic CMS
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2.
Affected products
- Statamic CMS: before 5.74.3 (fixed in 5.74.3); from 6.0.0, before 6.24.2 (fixed in 6.24.2)
Published 2026-08-06. Last modified 2026-09-08.