Kirby Kirby是Kirby个人开发者的一款服务器与网络设备产品。 Kirby 4.9.1之前版本和5.4.1之前版本存在跨站脚本漏洞,该漏洞源于对列表字段内容保存时未进行安全清理,导致容易受到跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44177 | Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup | |
| CVE-2026-44174 | Kirby: Arbitrary Method Call via REST API search and collection query endpoints | |
| CVE-2026-44176 | Kirby: `pages.access` permission is not checked during rendering of page drafts | |
| CVE-2026-45368 | Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site fro | |
| CVE-2026-45334 | Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list |
No comments yet