statamic/cms is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Statamic's default (automagic) form notification email renders user-submitted form values without escaping them. An unauthenticated visitor who submits a public frontend form can inject HTML into the notification email delivered to the configured recipients. Before the fix these submitted values were placed into the email body unescaped, producing stored cross-site scripting against the recipients who open the email. The fix escapes submitted values when building the automagic notification email.
You are affected if you are using a version that falls within the vulnerable range and your site sends the default automagic email notification for a public frontend form.
statamic/cms is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 5.74.2 and 6.0.0 - 6.24.1.
Upgrade the statamic/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant