VYPR

Kirby CMS

by Kirby CMS

Source repositories

CVEs (7)

  • CVE-2026-75594HigAug 31, 2026
    risk 0.46cvss epss 0.01

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's…

  • CVE-2018-16627MedDec 20, 2018
    risk 0.40cvss 6.1epss 0.01

    panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

  • CVE-2026-69127MedAug 7, 2026
    risk 0.38cvss epss 0.00

    Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability…

  • CVE-2018-16624MedMay 13, 2019
    risk 0.35cvss 5.4epss 0.01

    panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.

  • CVE-2018-16628MedDec 4, 2018
    risk 0.35cvss 5.4epss 0.01

    panel/login in Kirby v2.5.12 allows XSS via a blog name.

  • CVE-2018-16623MedMay 13, 2019
    risk 0.31cvss 4.8epss 0.01

    Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.

  • CVE-2024-26484MedFeb 22, 2024
    risk 0.00cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any…