Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vx89-p3j7-8xqc | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 08 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2. | |
| Title | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-08T02:31:25.913Z
Reserved: 2026-08-06T16:28:51.183Z
Link: CVE-2026-71435
Updated: 2026-08-08T02:31:19.854Z
Status : Received
Published: 2026-08-06T22:18:30.423
Modified: 2026-08-08T03:16:47.430
Link: CVE-2026-71435
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:45:05Z
Github GHSA