Kirby CMS
Products
2- 7 CVEs
- 1 CVE
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-75594 | Hig | 0.46 | — | 0.01 | Aug 31, 2026 | Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's… | ||
| CVE-2018-16627 | Med | 0.40 | 6.1 | 0.01 | Dec 20, 2018 | panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. | ||
| CVE-2026-69127 | Med | 0.38 | — | 0.00 | Aug 7, 2026 | Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability… | ||
| CVE-2018-16624 | Med | 0.35 | 5.4 | 0.01 | May 13, 2019 | panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page. | ||
| CVE-2018-16628 | Med | 0.35 | 5.4 | 0.01 | Dec 4, 2018 | panel/login in Kirby v2.5.12 allows XSS via a blog name. | ||
| CVE-2018-16623 | Med | 0.31 | 4.8 | 0.01 | May 13, 2019 | Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown. | ||
| CVE-2024-26484 | Med | 0.00 | 6.1 | 0.00 | Feb 22, 2024 | A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any… |
- risk 0.46cvss —epss 0.01
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's…
- risk 0.40cvss 6.1epss 0.01
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
- risk 0.38cvss —epss 0.00
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability…
- risk 0.35cvss 5.4epss 0.01
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
- risk 0.35cvss 5.4epss 0.01
panel/login in Kirby v2.5.12 allows XSS via a blog name.
- risk 0.31cvss 4.8epss 0.01
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
- risk 0.00cvss 6.1epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any…