VendorsGetkirbykirby2.5.12
Vulnerabilities

Getkirby Kirby 2.5.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-16627
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
Published 2018-12-20 · Modified
6.1EPSS 0.008
CVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
Published 2022-08-24 · Modified
5.4EPSS 0.007
CVE-2018-16624
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
Published 2019-05-13 · Modified
5.4EPSS 0.007
CVE-2018-16628
panel/login in Kirby v2.5.12 allows XSS via a blog name.
Published 2018-12-04 · Modified
5.4EPSS 0.006
CVE-2018-16623
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
Published 2019-05-13 · Modified
4.8EPSS 0.007
CVE-2018-16630
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
Published 2018-12-28 · Modified
4.8EPSS 0.006
CVE-2018-14519
An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.
Published 2022-08-24 · Modified
4.3EPSS 0.005