VendorsGetkirbykirbyall versions
Vulnerabilities

Getkirby Kirby

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

41CVEs
CVE-2023-38490
Kirby XML External Entity (XXE) vulnerability in the XML data handler
Published 2023-07-27 · Modified
10.0EPSS 0.017
CVE-2020-26255
PHP Phar archives could be uploaded and executed in Kirby
Published 2020-12-08 · Modified
9.1EPSS 0.015
CVE-2025-30159
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
Published 2025-05-13 · Analyzed
9.1EPSS 0.007
CVE-2025-31493
Path traversal of collection names during file system lookup
Published 2025-05-13 · Analyzed
9.1EPSS 0.006
CVE-2024-26483
An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.
Published 2024-02-22 · Analyzed
8.8EPSS 0.010
CVE-2023-38488
Kirby vulnerable to field injection in the KirbyData text storage handler
Published 2023-07-27 · Modified
8.8EPSS 0.009
CVE-2026-41325
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
Published 2026-04-24 · Analyzed
8.8EPSS 0.005
CVE-2024-41964
Insufficient permission checks in the language settings in Kirby CMS
Published 2024-08-29 · Analyzed
8.1EPSS 0.005
CVE-2026-34587
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
Published 2026-04-24 · Analyzed
8.1EPSS 0.005
CVE-2021-29460
Cross-site scripting (XSS) from unsanitized uploaded SVG files
Published 2021-04-27 · Modified
7.61 PoCEPSS 0.032
CVE-2023-38492
Kirby vulnerable to denial of service from unlimited password lengths
Published 2023-07-27 · Modified
7.5EPSS 0.012
CVE-2025-30207
Kirby vulnerable to path traversal in the router for PHP's built-in server
Published 2025-05-13 · Analyzed
7.5EPSS 0.006
CVE-2026-32870
Kirby has XML injection in its XML creator toolkit
Published 2026-04-24 · Analyzed
7.5EPSS 0.005
CVE-2021-41252
Cross-site scripting (XSS) from writer field content in the site frontend
Published 2021-11-16 · Modified
7.3EPSS 0.009
CVE-2023-38489
Kirby vulnerable to Insufficient Session Expiration after a password change
Published 2023-07-27 · Modified
7.3EPSS 0.008
CVE-2021-41258
Cross-site scripting (XSS) from image block content in the site frontend
Published 2021-11-16 · Modified
7.3EPSS 0.008
CVE-2021-32735
Cross-site scripting (XSS) from field and configuration text displayed in the Panel
Published 2021-07-02 · Modified
7.1EPSS 0.005
CVE-2026-42069
Kirby: Read access to site, user and role information is not gated by permissions
Published 2026-05-09 · Analyzed
7.1EPSS 0.004
CVE-2026-42137
Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog
Published 2026-05-09 · Analyzed
7.1EPSS 0.004
CVE-2024-26482
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization such that the reporter's mentioned "injecting malicious scripts" would not occur.
Published 2024-02-22 · Analyzed
7.1EPSS 0.003
CVE-2020-26253
.dev domains treated as local in Kirby
Published 2020-12-08 · Modified
6.8EPSS 0.006
CVE-2022-39315
Kirby CMS vulnerable to user enumeration in the brute force protection
Published 2022-10-25 · Modified
6.5EPSS 0.006
CVE-2026-29905
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file for metadata or thumbnail generation, it triggers a fatal TypeError.
Published 2026-03-26 · Analyzed
6.5EPSS 0.006
CVE-2026-40099
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Published 2026-04-24 · Analyzed
6.5EPSS 0.004
CVE-2018-16627
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
Published 2018-12-20 · Modified
6.1EPSS 0.008
CVE-2024-26484
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any version of Kirby CMS. The only effect was on the trykirby.com demo site, which is not customer-controlled.
Published 2024-02-22 · Analyzed
6.1EPSS 0.004
CVE-2022-36037
Cross-site scripting (XSS) from dynamic options in the multiselect field in Kirby
Published 2022-08-29 · Modified
5.9EPSS 0.009
CVE-2026-21896
Kirby is missing permission checks in the content changes API
Published 2026-01-08 · Analyzed
5.8EPSS 0.002
CVE-2023-38491
Kirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded files
Published 2023-07-27 · Modified
5.7EPSS 0.006
CVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
Published 2022-08-24 · Modified
5.4EPSS 0.007
CVE-2018-16624
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
Published 2019-05-13 · Modified
5.4EPSS 0.007
CVE-2018-16628
panel/login in Kirby v2.5.12 allows XSS via a blog name.
Published 2018-12-04 · Modified
5.4EPSS 0.006
CVE-2024-27087
Kirby cross-site scripting (XSS) in the link field "Custom" type
Published 2024-02-26 · Analyzed
5.4EPSS 0.003
CVE-2025-65012
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Published 2025-11-18 · Analyzed
5.4EPSS 0.002
CVE-2026-42051
Kirby: System API endpoint leaks license data and installed version to authenticated users
Published 2026-05-09 · Analyzed
5.3EPSS 0.003
CVE-2026-42174
Kirby: User avatar creation, replacement and deletion are not gated by user update permissions
Published 2026-05-09 · Analyzed
5.3EPSS 0.003
CVE-2018-16623
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
Published 2019-05-13 · Modified
4.8EPSS 0.007
CVE-2018-16630
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
Published 2018-12-28 · Modified
4.8EPSS 0.006
CVE-2022-39314
User enumeration in the code-based login and password reset forms
Published 2022-10-24 · Modified
4.8EPSS 0.004
CVE-2024-26481
Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.
Published 2024-02-22 · Analyzed
4.7EPSS 0.004
1 / 2Next →