statamic/cms is vulnerable to Cross-site Scripting (XSS)
75
High Risk
Affected versions of the package expose a Cross-site Scripting (XSS) vulnerability due to improper sanitization of certain fields in the control panel, which allows attacker-controlled user input to execute malicious scripts.
You are affected if you are using a version that falls within the vulnerable range.
statamic/cms is vulnerable to Cross-site Scripting (XSS) in versions 3.0.0 - 4.58.2 and 5.0.0 - 5.22.0.
Upgrade the statamic/cms library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant