statamic/cms Security Advisories for v6.24.0 (2)
-
[MEDIUM] Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
PKSA-h7t4-kgpy-prgj CVE-2026-71435 GHSA-vx89-p3j7-8xqc
Affected version: >=6.0.0,<6.24.2|<5.74.3
Reported by:
GitHub -
[MEDIUM] Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
PKSA-htv4-42tq-8d9c CVE-2026-71434 GHSA-qhr7-v3xp-vw9m
Affected version: >=6.0.0,<6.24.2|<5.74.3
Reported by:
GitHub