Kirby Kirby是Kirby个人开发者的一款服务器与网络设备产品。 Kirby 4.9.1之前版本和5.0.0至5.4.1之前版本存在代码注入漏洞,该漏洞源于未验证用于集合查询的模型属性,可能允许攻击者在查询中包含任意模型方法,包括暴露密码哈希、绝对路径等敏感数据的方法,以及导致权限提升或批量删除模型等操作的方法。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44175 | Kirby: Cross-site scripting (XSS) from list field content in the site frontend | |
| CVE-2026-44177 | Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup | |
| CVE-2026-44176 | Kirby: `pages.access` permission is not checked during rendering of page drafts | |
| CVE-2026-45368 | Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site fro | |
| CVE-2026-45334 | Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list |
No comments yet