VYPR
Moderate severityNVD Advisory· Published Feb 22, 2024· Updated Aug 14, 2024

CVE-2024-26481

CVE-2024-26481

Description

Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Kirby CMS 4.1.0 and earlier versions contain a reflected self-XSS in the URL field, allowing social engineering attacks.

Vulnerability

Overview

CVE-2024-26481 describes a reflected self-XSS vulnerability in Kirby CMS v4.1.0, which also affects earlier versions. The issue resides in the URL field blueprint, where user-entered URLs are copied directly into the link target of a button without validation. When a user clicks the link icon with Ctrl+Click/Cmd+Click, a javascript: URL can execute arbitrary JavaScript in the user's own browser context. [1][2]

Exploitation

This is a self-XSS (reflected XSS) vulnerability requiring social engineering. An attacker must trick a Panel user into clicking a crafted link or pasting malicious code. The attack cannot be automated and requires knowledge of the content structure. The malicious JavaScript runs only in the victim's session, not affecting other users. [2]

Impact

Successful exploitation allows the attacker to execute JavaScript in the Panel session of the victim, potentially triggering API requests with the victim's permissions. This could lead to privilege escalation if the victim is an admin, or allow data theft and other malicious actions. [2]

Mitigation

The vulnerability has been patched in Kirby versions 3.6.6.5, 3.7.5.4, 3.8.4.3, 3.9.8.1, 3.10.0.1, and 4.1.1. Users are advised to update to the latest patched release. No workarounds are mentioned, but avoiding clicking suspicious links in the Panel can reduce risk. [1][2]

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
getkirby/cmsPackagist
< 3.6.6.53.6.6.5
getkirby/cmsPackagist
>= 3.7.0, < 3.7.5.43.7.5.4
getkirby/cmsPackagist
>= 3.8.0, < 3.8.4.33.8.4.3
getkirby/cmsPackagist
>= 3.9.0, < 3.9.8.13.9.8.1
getkirby/cmsPackagist
>= 3.10.0, < 3.10.0.13.10.0.1
getkirby/cmsPackagist
>= 4.0.0, < 4.1.14.1.1

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.