
📧 Statamic CMS vulnerable to email HTML injection CVE-2026-71435 affects Statamic before: • 5.74.3 • 6.24.2 Unauthenticated users submitting forms could inject HTML content into notification emails because submitted values were rendered without proper escaping. ✅ Fixed in 5.74.3 and 6.24.2. 🔎 Source: Tenable / GitHub Security Advisory. #Statamic #Laravel #AppSec #CVE #CyberSecurity
Post summary
Statamic CMS before versions 5.74.3 and 6.24.2 is vulnerable to unauthenticated HTML injection through form submissions; the problem has been fixed in those releases.
