PT-2026-28550 · Statamic · Statamic

CVE-2026-33883

·

Publicado

2026-03-26

·

Atualizado

2026-03-28

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 5.73.16 Statamic versions prior to 6.7.2
Description The user:reset password form tag does not properly escape user-supplied input before rendering it as HTML, potentially allowing an attacker to inject and execute arbitrary JavaScript code in a victim's browser. This can be achieved by crafting a malicious URL. The vulnerable component is the user:reset password form tag. The vulnerable parameter is user input.
Recommendations Update to Statamic version 5.73.16 or later. Update to Statamic version 6.7.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33883
GHSA-3JG4-P23X-P4QX

Produtos afetados

Statamic