VYPR

Kirby

by Getkirby

Source repositories

CVEs (57)

  • CVE-2021-41252HigNov 16, 2021
    risk 0.41cvss 7.3epss 0.01

    Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would…

  • CVE-2018-16627MedDec 20, 2018
    risk 0.40cvss 6.1epss 0.01

    panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

  • CVE-2026-71415HigAug 31, 2026
    risk 0.39cvss —epss 0.00

    Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Api\Upload::processChunk() persisted chunk…

  • CVE-2026-54005HigJul 9, 2026
    risk 0.39cvss —epss 0.00

    Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including full content and metadata, for…

  • CVE-2023-38488HigJul 27, 2023
    risk 0.39cvss 7.1epss 0.01

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update a Kirby…

  • CVE-2021-32735HigJul 2, 2021
    risk 0.39cvss 7.1epss 0.01

    Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious…

  • CVE-2026-75592MedAug 31, 2026
    risk 0.38cvss —epss 0.00

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Kirby\Filesystem\Dir::realpath() and…

  • CVE-2026-50188MedJul 9, 2026
    risk 0.38cvss —epss 0.00

    Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could…

  • CVE-2023-38490MedJul 27, 2023
    risk 0.37cvss 6.8epss 0.02

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in site or plugin code. The Kirby…

  • CVE-2020-26255MedDec 8, 2020
    risk 0.37cvss 6.8epss 0.01

    Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on the server. This vulnerability is critical if you might have potential attackers…

  • CVE-2020-26253MedDec 8, 2020
    risk 0.37cvss 6.8epss 0.01

    Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. In order to protect new installations on public servers that don't have an admin…

  • CVE-2026-40099MedApr 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also…

  • CVE-2026-29905MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to…

  • CVE-2022-39315MedOct 25, 2022
    risk 0.35cvss 6.5epss 0.01

    Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only be exploited for targeted attacks…

  • CVE-2018-14520MedAug 24, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.

  • CVE-2018-16624MedMay 13, 2019
    risk 0.35cvss 5.4epss 0.01

    panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.

  • CVE-2018-16628MedDec 4, 2018
    risk 0.35cvss 5.4epss 0.01

    panel/login in Kirby v2.5.12 allows XSS via a blog name.

  • CVE-2026-54004MedJul 9, 2026
    risk 0.34cvss —epss 0.01

    Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs without checking page access…

  • CVE-2026-44176MedJul 16, 2026
    risk 0.32cvss —epss 0.00

    Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are defined for each user role in the user blueprint (site/blueprints/users/...). It is also possible to…

  • CVE-2024-26481MedFeb 22, 2024
    risk 0.31cvss 4.7epss 0.00

    Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.