Getkirby

Kirby

58 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.17%
  • Veröffentlicht 27.04.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:01:08

Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim open...

  • EPSS 1.47%
  • Veröffentlicht 08.12.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:40

Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on the server. This vulnerability is critical if you mi...

  • EPSS 0.56%
  • Veröffentlicht 08.12.2020 02:15:10
  • Zuletzt bearbeitet 21.11.2024 05:19:40

Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. In order to protect new installations on public serv...

Exploit
  • EPSS 0.7%
  • Veröffentlicht 13.05.2019 13:29:01
  • Zuletzt bearbeitet 21.11.2024 03:53:04

panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.

Exploit
  • EPSS 0.68%
  • Veröffentlicht 13.05.2019 13:29:01
  • Zuletzt bearbeitet 21.11.2024 03:53:04

Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.

Exploit
  • EPSS 0.56%
  • Veröffentlicht 28.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:05

Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.

Exploit
  • EPSS 0.75%
  • Veröffentlicht 20.12.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:05

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 04.12.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:05

panel/login in Kirby v2.5.12 allows XSS via a blog name.