Résumé
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Détails de l’avis
Impact
The default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients
Patches
This has been fixed in 5.74.3 and 6.24.2.
Références
- https://github.com/advisories/GHSA-vx89-p3j7-8xqc
- https://github.com/statamic/cms/security/advisories/GHSA-vx89-p3j7-8xqc
- https://github.com/statamic/cms/pull/14959
- https://github.com/statamic/cms/commit/4ad1335e818a67249d0617f0f167a1198fb96a2c
- https://github.com/statamic/cms/releases/tag/v5.74.3
- https://github.com/statamic/cms/releases/tag/v6.24.2
Vulnérabilités liées
Tout Supply chain →- MEDIUMCVE-2026-63670
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
- MEDIUMCVE-2026-73295
Material for MkDocs: DOM XSS in search suggestions via query parameter
- HIGHGHSA-99rq-75j6-5j9f
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
- MEDIUMCVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
- MEDIUMCVE-2026-82396
Sulu: Stored XSS via media download inline-disposition override
- MEDIUMGHSA-cp6q-959q-f8rh
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes