HTML Injection Vulnerability in Statamic CMS by Statamic
CVE-2026-71435

6.1MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-71435?

Prior to versions 5.74.3 and 6.24.2, Statamic CMS was susceptible to an HTML injection vulnerability due to improper rendering of user-submitted values in the notification emails. This flaw allows unauthenticated users to inject malicious HTML into emails that are sent to designated recipients, potentially compromising the security of the information transmitted. The issue has been addressed in the latest releases, and users are advised to update their systems to protect against possible exploitation.

Affected Version(s)

cms < 5.74.3 < 5.74.3

cms >= 6.0.0, < 6.24.2 < 6.0.0, 6.24.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.