
CVE-2026-28424 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the … https://www.cve.org/CVERecord?id=CVE-2026-28424
Post summary
CVE-2026-28424 is a data disclosure flaw in Statmatic CMS that exposed user email addresses in responses; the issue is fixed in versions 5.73.11 and 6.4.0.

