Cross-Site Scripting Vulnerability in Statamic CMS by Statamic
CVE-2026-33883

6.1MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33883?

Statamic, a robust content management system built on Laravel and Git, has a vulnerability that allows for cross-site scripting (XSS) attacks. In versions earlier than 5.73.16 and 6.7.2, the user:reset_password_form tag was capable of rendering user input directly into HTML without proper escaping. This flaw enables malicious actors to craft URLs containing arbitrary JavaScript, which could be executed in the browsers of unsuspecting users. Upgrading to the latest versions is essential to mitigate this security risk.

Affected Version(s)

cms < 5.73.16 < 5.73.16

cms >= 6.0.0-alpha.1, < 6.7.2 < 6.0.0-alpha.1, 6.7.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.