Skip to content

Statamic is vulnerable to account takeover via password reset link injection

Critical severity GitHub Reviewed Published Feb 23, 2026 in statamic/cms • Updated Feb 27, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts