PT-2026-68986 · Packagist · Statamic Cms

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Impact

The default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients

Patches

This has been fixed in 5.74.3 and 6.24.2.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-VX89-P3J7-8XQC

Affected Products

Statamic Cms