Vulnerability Description
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Statamic | Statamic | < 5.73.11 |
Related Weaknesses (CWE)
References
- https://github.com/statamic/cms/releases/tag/v5.73.11Release Notes
- https://github.com/statamic/cms/releases/tag/v6.4.0Release Notes
- https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63PatchVendor Advisory
FAQ
What is CVE-2026-28424?
CVE-2026-28424 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for...
How severe is CVE-2026-28424?
CVE-2026-28424 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-28424?
Check the references section above for vendor advisories and patch information. Affected products include: Statamic Statamic.