Getkirby

Kirby

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Veröffentlicht 27.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:13:41

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). The real-world impact of th...

  • EPSS 0.55%
  • Veröffentlicht 27.07.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visi...

  • EPSS 1.53%
  • Veröffentlicht 27.07.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in si...

  • EPSS 0.72%
  • Veröffentlicht 27.07.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a ...

  • EPSS 0.8%
  • Veröffentlicht 27.07.2023 15:15:11
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visi...

  • EPSS 0.59%
  • Veröffentlicht 25.10.2022 17:15:55
  • Zuletzt bearbeitet 21.11.2024 07:18:01

Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only be exploite...

  • EPSS 0.35%
  • Veröffentlicht 24.10.2022 14:15:51
  • Zuletzt bearbeitet 30.01.2026 20:16:35

Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code...

  • EPSS 0.67%
  • Veröffentlicht 29.08.2022 18:15:09
  • Zuletzt bearbeitet 21.11.2024 07:12:14

kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting (XSS) is a type of vulnerability that allows execution of any kind of JavaScript code inside the Pane...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 24.08.2022 20:15:08
  • Zuletzt bearbeitet 17.06.2025 20:15:23

An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 24.08.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 03:49:14

An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.