Getkirby

Kirby

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 24.08.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 03:49:14

An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.

  • EPSS 0.52%
  • Veröffentlicht 16.11.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:54

Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used in block snippets to convert the blocks to HTML for use in your templates. We recommend to escape HTM...

  • EPSS 0.45%
  • Veröffentlicht 16.11.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:53

Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, oth...

  • EPSS 0.38%
  • Veröffentlicht 02.07.2021 15:15:10
  • Zuletzt bearbeitet 21.11.2024 06:07:38

Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) ...

Exploit
  • EPSS 1.12%
  • Veröffentlicht 27.04.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:08

Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim open...

  • EPSS 1.11%
  • Veröffentlicht 08.12.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:40

Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on the server. This vulnerability is critical if you mi...

  • EPSS 0.16%
  • Veröffentlicht 08.12.2020 02:15:10
  • Zuletzt bearbeitet 21.11.2024 05:19:40

Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. In order to protect new installations on public serv...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 13.05.2019 13:29:01
  • Zuletzt bearbeitet 21.11.2024 03:53:04

panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 13.05.2019 13:29:01
  • Zuletzt bearbeitet 21.11.2024 03:53:04

Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 28.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:05

Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.