Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser. This has been fixed in 5.73.16 and 6.7.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3jg4-p23x-p4qx | Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag |
References
History
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser. This has been fixed in 5.73.16 and 6.7.2. | |
| Title | Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T20:37:21.190Z
Reserved: 2026-03-24T15:10:05.681Z
Link: CVE-2026-33883
No data.
Status : Received
Published: 2026-03-27T21:17:25.027
Modified: 2026-03-27T21:17:25.027
Link: CVE-2026-33883
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA