CVE-2026-75594
- EPSS 0.51%
- Veröffentlicht 31.08.2026 20:53:00
- Zuletzt bearbeitet 08.09.2026 21:11:31
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media dire...
CVE-2026-75592
- EPSS 0.46%
- Veröffentlicht 31.08.2026 20:49:41
- Zuletzt bearbeitet 08.09.2026 21:11:31
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Kirby\Filesyste...
CVE-2026-71415
- EPSS 0.25%
- Veröffentlicht 31.08.2026 20:46:02
- Zuletzt bearbeitet 08.09.2026 21:11:31
Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Api\Upload::pro...
CVE-2026-69127
- EPSS 0.29%
- Veröffentlicht 07.08.2026 18:33:19
- Zuletzt bearbeitet 16.09.2026 13:42:42
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API...
CVE-2026-45368
- EPSS 0.33%
- Veröffentlicht 16.07.2026 22:17:02
- Zuletzt bearbeitet 18.07.2026 05:16:53
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. The vulnerabil...
CVE-2026-45334
- EPSS 0.22%
- Veröffentlicht 16.07.2026 22:17:02
- Zuletzt bearbeitet 17.07.2026 19:17:14
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information without checking the requesting user's access permissions. Kirby's Panel includes a content-locking feature...
CVE-2026-44175
- EPSS 0.25%
- Veröffentlicht 16.07.2026 21:36:06
- Zuletzt bearbeitet 17.07.2026 18:04:04
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field on save, leaving it vulnerable to cross-site scripting (XSS). Kirby's list field stores its format...
- EPSS 0.22%
- Veröffentlicht 16.07.2026 21:24:04
- Zuletzt bearbeitet 17.07.2026 18:04:04
Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are defined for each user role in the user blueprint (site/blueprints/users/...)...
CVE-2026-44177
- EPSS 0.45%
- Veröffentlicht 16.07.2026 21:19:16
- Zuletzt bearbeitet 17.07.2026 18:04:04
Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path traversal vulnerability. Version 5.3.0 introduced a performance improvement ...
CVE-2026-44174
- EPSS 0.28%
- Veröffentlicht 16.07.2026 21:13:43
- Zuletzt bearbeitet 18.07.2026 05:16:53
Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing attackers to include arbitrary model methods in their queries. This includes m...