CVE-2026-69127
- EPSS 0.29%
- Veröffentlicht 07.08.2026 18:33:19
- Zuletzt bearbeitet 11.08.2026 23:18:06
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API...
CVE-2026-45368
- EPSS 0.33%
- Veröffentlicht 16.07.2026 22:17:02
- Zuletzt bearbeitet 18.07.2026 05:16:53
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. The vulnerabil...
CVE-2026-45334
- EPSS 0.22%
- Veröffentlicht 16.07.2026 22:17:02
- Zuletzt bearbeitet 17.07.2026 19:17:14
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information without checking the requesting user's access permissions. Kirby's Panel includes a content-locking feature...
CVE-2026-44175
- EPSS 0.25%
- Veröffentlicht 16.07.2026 21:36:06
- Zuletzt bearbeitet 17.07.2026 18:04:04
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field on save, leaving it vulnerable to cross-site scripting (XSS). Kirby's list field stores its format...
- EPSS 0.22%
- Veröffentlicht 16.07.2026 21:24:04
- Zuletzt bearbeitet 17.07.2026 18:04:04
Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are defined for each user role in the user blueprint (site/blueprints/users/...)...
CVE-2026-44177
- EPSS 0.45%
- Veröffentlicht 16.07.2026 21:19:16
- Zuletzt bearbeitet 17.07.2026 18:04:04
Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path traversal vulnerability. Version 5.3.0 introduced a performance improvement ...
CVE-2026-44174
- EPSS 0.28%
- Veröffentlicht 16.07.2026 21:13:43
- Zuletzt bearbeitet 18.07.2026 05:16:53
Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing attackers to include arbitrary model methods in their queries. This includes m...
CVE-2026-49276
- EPSS 0.29%
- Veröffentlicht 09.07.2026 18:48:50
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the targe...
CVE-2026-54005
- EPSS 0.27%
- Veröffentlicht 09.07.2026 18:47:02
- Zuletzt bearbeitet 14.07.2026 02:16:55
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including ful...
CVE-2026-50188
- EPSS 0.29%
- Veröffentlicht 09.07.2026 18:44:56
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data...