High severityNVD Advisory· Published Jul 9, 2026· Updated Jul 10, 2026
CVE-2026-49276
CVE-2026-49276
Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getkirby/cmsPackagist | < 4.9.4 | 4.9.4 |
getkirby/cmsPackagist | >= 5.0.0-alpha.1, < 5.4.4 | 5.4.4 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Kirby CMS: Seven Bugs Patched in One Advisory, Including Critical Auth BypassVypr Intelligence · Jun 18, 2026