Getkirby

Kirby

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 22.02.2024 05:15:10
  • Zuletzt bearbeitet 21.08.2025 14:08:02

A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that ...

Exploit
  • EPSS 0.97%
  • Veröffentlicht 22.02.2024 05:15:09
  • Zuletzt bearbeitet 08.04.2025 14:35:43

An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 22.02.2024 05:15:09
  • Zuletzt bearbeitet 21.08.2025 14:03:18

An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitiz...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 22.02.2024 05:15:09
  • Zuletzt bearbeitet 08.04.2025 14:14:12

Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.

  • EPSS 1.18%
  • Veröffentlicht 27.07.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:13:41

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). The real-world impact of th...

  • EPSS 0.62%
  • Veröffentlicht 27.07.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visi...

  • EPSS 1.7%
  • Veröffentlicht 27.07.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in si...

  • EPSS 0.81%
  • Veröffentlicht 27.07.2023 15:15:12
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a ...

  • EPSS 0.92%
  • Veröffentlicht 27.07.2023 15:15:11
  • Zuletzt bearbeitet 21.11.2024 08:13:40

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visi...

  • EPSS 0.61%
  • Veröffentlicht 25.10.2022 17:15:55
  • Zuletzt bearbeitet 21.11.2024 07:18:01

Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only be exploite...