Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54005 | Kirby: `pages.access` permission is not checked in the `site/find` REST API route | |
| CVE-2026-54003 | Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` h | |
| CVE-2026-54002 | Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize( | |
| CVE-2026-49276 | Kirby: Self cross-site scripting (self-XSS) in the writer field | |
| CVE-2026-49274 | Kirby: `pages.access` permission is not checked in the pages picker for parent pages | |
| CVE-2026-50188 | Kirby: Request header injection in `Http\Remote` |
No comments yet