VYPR
High severityNVD Advisory· Published Feb 22, 2024· Updated Aug 29, 2024

CVE-2024-26482

CVE-2024-26482

Description

An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization such that the reporter's mentioned "injecting malicious scripts" would not occur.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An HTML injection vulnerability was reported in Kirby CMS v4.1.0's Edit Content Layout module, though the vendor disputes its severity due to backend sanitization that prevents script execution.

CVE-2024-26482 describes an HTML injection vulnerability in the Edit Content Layout module of Kirby CMS version 4.1.0. The flaw allows an attacker to inject arbitrary HTML into content fields, though the vendor notes that such formatting (e.g., using H1 tags) is an expected feature of the editor [1].

The issue can potentially be exploited by any user with access to the content editing interface, as the vulnerability exists in a module used for layout modification. However, the vendor emphasizes that backend sanitization prevents the injection of malicious scripts, and therefore the risk of cross-site scripting (XSS) is mitigated [1].

Kirby CMS is a widely used file-based content management system. While HTML injection can theoretically alter page appearance or lead to phishing attacks in certain contexts, the backend filtering reduces the practical impact. The vendor has disputed the significance of the report, and as of February 2024, no security update has been released specifically for this issue [1][2].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
getkirby/cmsPackagist
<= 4.1.0

Affected products

28

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.