Skip to content

Statamic is vulnerable to account takeover via password reset link injection

Critical severity GitHub Reviewed Published Feb 23, 2026 in statamic/cms • Updated Mar 19, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts