Cross-Site Scripting Vulnerability in Statamic CMS by Statamic
CVE-2026-33883
6.1MEDIUM
What is CVE-2026-33883?
Statamic, a robust content management system built on Laravel and Git, has a vulnerability that allows for cross-site scripting (XSS) attacks. In versions earlier than 5.73.16 and 6.7.2, the user:reset_password_form tag was capable of rendering user input directly into HTML without proper escaping. This flaw enables malicious actors to craft URLs containing arbitrary JavaScript, which could be executed in the browsers of unsuspecting users. Upgrading to the latest versions is essential to mitigate this security risk.
Affected Version(s)
cms < 5.73.16 < 5.73.16
cms >= 6.0.0-alpha.1, < 6.7.2 < 6.0.0-alpha.1, 6.7.2
