CVE-2026-21896
- EPSS 0.03%
- Veröffentlicht 08.01.2026 18:15:59
- Zuletzt bearbeitet 02.02.2026 19:02:51
Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(...
CVE-2025-65012
- EPSS 0.04%
- Veröffentlicht 18.11.2025 22:44:11
- Zuletzt bearbeitet 26.11.2025 16:25:06
Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, ma...
CVE-2025-31493
- EPSS 0.21%
- Veröffentlicht 13.05.2025 15:24:40
- Zuletzt bearbeitet 26.08.2025 14:33:24
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a...
CVE-2025-30207
- EPSS 0.16%
- Veröffentlicht 13.05.2025 15:20:00
- Zuletzt bearbeitet 26.08.2025 14:44:44
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use ...
CVE-2025-30159
- EPSS 0.31%
- Veröffentlicht 13.05.2025 15:15:56
- Zuletzt bearbeitet 26.08.2025 14:48:11
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet ...
CVE-2024-41964
- EPSS 0.38%
- Veröffentlicht 29.08.2024 17:15:07
- Zuletzt bearbeitet 06.09.2024 22:56:18
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and deleting languages have already existed and could be ...
CVE-2024-27087
- EPSS 0.78%
- Veröffentlicht 26.02.2024 17:15:10
- Zuletzt bearbeitet 31.12.2024 15:34:15
Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link to the relevant URL format. It also includes a "Custom" link type for advanced use cases that don't...
CVE-2024-26484
- EPSS 0.09%
- Veröffentlicht 22.02.2024 05:15:10
- Zuletzt bearbeitet 21.08.2025 14:08:02
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that ...
CVE-2024-26483
- EPSS 0.16%
- Veröffentlicht 22.02.2024 05:15:09
- Zuletzt bearbeitet 08.04.2025 14:35:43
An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.
CVE-2024-26482
- EPSS 0.04%
- Veröffentlicht 22.02.2024 05:15:09
- Zuletzt bearbeitet 21.08.2025 14:03:18
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitiz...