CVE-2021-29460
- EPSS 3.17%
- Veröffentlicht 27.04.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:08
Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim open...
CVE-2020-26255
- EPSS 1.47%
- Veröffentlicht 08.12.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:19:40
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on the server. This vulnerability is critical if you mi...
CVE-2020-26253
- EPSS 0.56%
- Veröffentlicht 08.12.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 05:19:40
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. In order to protect new installations on public serv...
CVE-2018-16624
- EPSS 0.7%
- Veröffentlicht 13.05.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:04
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
CVE-2018-16623
- EPSS 0.68%
- Veröffentlicht 13.05.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:04
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
CVE-2018-16630
- EPSS 0.56%
- Veröffentlicht 28.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:05
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
CVE-2018-16627
- EPSS 0.75%
- Veröffentlicht 20.12.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:05
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
CVE-2018-16628
- EPSS 0.57%
- Veröffentlicht 04.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:05
panel/login in Kirby v2.5.12 allows XSS via a blog name.