CVE-2026-49276
- EPSS 0.29%
- Veröffentlicht 09.07.2026 18:48:50
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the targe...
CVE-2026-54005
- EPSS 0.27%
- Veröffentlicht 09.07.2026 18:47:02
- Zuletzt bearbeitet 14.07.2026 02:16:55
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including ful...
CVE-2026-50188
- EPSS 0.29%
- Veröffentlicht 09.07.2026 18:44:56
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data...
CVE-2026-54004
- EPSS 0.31%
- Veröffentlicht 09.07.2026 18:42:00
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for files stored in top-level draft pages to physical media URLs withou...
CVE-2026-49274
- EPSS 0.28%
- Veröffentlicht 09.07.2026 18:38:32
- Zuletzt bearbeitet 14.07.2026 02:16:55
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission disabled allowed authenticated users to provide an inaccessible parent page or site to the...
CVE-2026-54003
- EPSS 0.55%
- Veröffentlicht 09.07.2026 18:36:43
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request hea...
CVE-2026-54002
- EPSS 0.41%
- Veröffentlicht 09.07.2026 18:34:29
- Zuletzt bearbeitet 10.07.2026 15:49:19
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::sanitize(), Sane::sanitize(), Sane::Html::sanitize(), Sane::Svg::sanitize(), Sane::Xml::sanitize(), S...
CVE-2026-42174
- EPSS 0.24%
- Veröffentlicht 09.05.2026 03:39:06
- Zuletzt bearbeitet 24.07.2026 21:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
CVE-2026-42137
- EPSS 0.3%
- Veröffentlicht 09.05.2026 03:38:35
- Zuletzt bearbeitet 24.07.2026 19:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5....
CVE-2026-42051
- EPSS 0.19%
- Veröffentlicht 09.05.2026 03:37:42
- Zuletzt bearbeitet 24.07.2026 21:10:00
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patched in versions 4.9.0 and 5.4.0.