CVE-2026-71435Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-09: 108-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    📧 Statamic CMS vulnerable to email HTML injection CVE-2026-71435 affects Statamic before: • 5.74.3 • 6.24.2 Unauthenticated users submitting forms could inject HTML content into notification emails because submitted values were rendered without proper escaping. ✅ Fixed in 5.74.3 and 6.24.2. 🔎 Source: Tenable / GitHub Security Advisory. #Statamic #Laravel #AppSec #CVE #CyberSecurity

    Post summary

    Statamic CMS before versions 5.74.3 and 6.24.2 is vulnerable to unauthenticated HTML injection through form submissions; the problem has been fixed in those releases.

    0000056
    34 followersView on X

Explore more