CVE-2026-54004
- EPSS 0.31%
- Veröffentlicht 09.07.2026 18:42:00
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs withou...
CVE-2026-49274
- EPSS 0.28%
- Veröffentlicht 09.07.2026 18:38:32
- Zuletzt bearbeitet 14.07.2026 02:16:55
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or site to the...
CVE-2026-54003
- EPSS 0.55%
- Veröffentlicht 09.07.2026 18:36:43
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request hea...
CVE-2026-54002
- EPSS 0.41%
- Veröffentlicht 09.07.2026 18:34:29
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::sanitize(), Sane::sanitize(), Sane::Html::sanitize(), Sane::Svg::sanitize(), Sane::Xml::sanitize(), S...
CVE-2026-42174
- EPSS 0.24%
- Veröffentlicht 09.05.2026 03:39:06
- Zuletzt bearbeitet 24.07.2026 21:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
CVE-2026-42137
- EPSS 0.3%
- Veröffentlicht 09.05.2026 03:38:35
- Zuletzt bearbeitet 24.07.2026 19:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5....
CVE-2026-42051
- EPSS 0.19%
- Veröffentlicht 09.05.2026 03:37:42
- Zuletzt bearbeitet 24.07.2026 21:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patched in versions 4.9.0 and 5.4.0.
CVE-2026-42069
- EPSS 0.23%
- Veröffentlicht 09.05.2026 03:35:02
- Zuletzt bearbeitet 24.07.2026 21:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
CVE-2026-41325
- EPSS 0.36%
- Veröffentlicht 24.04.2026 01:16:12
- Zuletzt bearbeitet 27.04.2026 19:07:45
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprin...
CVE-2026-40099
- EPSS 0.28%
- Veröffentlicht 24.04.2026 01:16:12
- Zuletzt bearbeitet 27.04.2026 19:12:30
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprin...