Getkirby

Kirby

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 09.05.2026 03:39:06
  • Zuletzt bearbeitet 18.05.2026 13:00:08

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.

  • EPSS 0.3%
  • Veröffentlicht 09.05.2026 03:38:35
  • Zuletzt bearbeitet 18.05.2026 13:00:27

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5....

  • EPSS 0.19%
  • Veröffentlicht 09.05.2026 03:37:42
  • Zuletzt bearbeitet 18.05.2026 13:01:29

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patched in versions 4.9.0 and 5.4.0.

  • EPSS 0.23%
  • Veröffentlicht 09.05.2026 03:35:02
  • Zuletzt bearbeitet 18.05.2026 13:00:59

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versions 4.9.0 and 5.4.0.

  • EPSS 0.36%
  • Veröffentlicht 24.04.2026 01:16:12
  • Zuletzt bearbeitet 27.04.2026 19:07:45

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprin...

  • EPSS 0.28%
  • Veröffentlicht 24.04.2026 01:16:12
  • Zuletzt bearbeitet 27.04.2026 19:12:30

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprin...

  • EPSS 0.33%
  • Veröffentlicht 24.04.2026 01:16:12
  • Zuletzt bearbeitet 27.04.2026 19:15:27

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in...

  • EPSS 0.35%
  • Veröffentlicht 24.04.2026 01:16:11
  • Zuletzt bearbeitet 27.04.2026 19:21:18

Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a second time but allowed to pass through. However, prior...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 26.03.2026 00:00:00
  • Zuletzt bearbeitet 02.04.2026 17:28:02

Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function....

  • EPSS 0.19%
  • Veröffentlicht 08.01.2026 18:15:59
  • Zuletzt bearbeitet 02.02.2026 19:02:51

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(...