Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kirby — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in kirby, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the Kirby product, focusing on Common Weakness Enumeration (CWE) classifications and associated security tags. It collects detailed information regarding various security flaws identified within the Kirby content management system, covering vulnerabilities reported from 2015 through the present day. By analyzing these records, users can track vendor advisories related to specific versions of the software, understand the technical implications of distinct weakness classes such as improper input validation or insecure direct object references, and look up a product’s historical vulnerability trends to assess long-term security posture. The data includes both low-severity issues and critical flaws that have been publicly disclosed or patched, providing a comprehensive view of the product's attack surface over time. This aggregation serves as a reference point for security researchers, developers, and system administrators who need to evaluate the risk associated with deploying or maintaining Kirby instances. By presenting this information in a structured format, the page facilitates deeper analysis of how specific coding errors or configuration weaknesses have manifested across different releases, allowing stakeholders to make informed decisions about mitigation strategies and update schedules without relying on fragmented or incomplete data sources.

Vendor: getkirby

CVE ID Title CVSS Severity Published
CVE-2026-69127 Kirby: System path exposure from error messages in the REST API CWE-497 6.9 Medium 2026-08-07
CVE-2026-45368 Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend CWE-79 - - 2026-07-16
CVE-2026-45334 Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions CWE-862 - - 2026-07-16
CVE-2026-44175 Kirby: Cross-site scripting (XSS) from list field content in the site frontend CWE-79 - - 2026-07-16
CVE-2026-44176 Kirby: `pages.access` permission is not checked during rendering of page drafts CWE-862 - - 2026-07-16
CVE-2026-44177 Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup CWE-22 - - 2026-07-16
CVE-2026-44174 Kirby: Arbitrary Method Call via REST API search and collection query endpoints CWE-470 - - 2026-07-16
CVE-2026-49276 Kirby: Self cross-site scripting (self-XSS) in the writer field CWE-83 - - 2026-07-09
CVE-2026-54005 Kirby: `pages.access` permission is not checked in the `site/find` REST API route CWE-862 - - 2026-07-09
CVE-2026-50188 Kirby: Request header injection in `Http\Remote` CWE-93 - - 2026-07-09
CVE-2026-54004 Kirby: Access to files of top-level drafts is not protected by permissions CWE-862 - - 2026-07-09
CVE-2026-49274 Kirby: `pages.access` permission is not checked in the pages picker for parent pages CWE-862 - - 2026-07-09
CVE-2026-54003 Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header CWE-454 - - 2026-07-09
CVE-2026-54002 Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()` CWE-79 - - 2026-07-09
CVE-2026-42174 Kirby: User avatar creation, replacement and deletion are not gated by user update permissions CWE-862 4.3 - 2026-05-09
CVE-2026-42137 Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog CWE-862 8.2 - 2026-05-09
CVE-2026-42051 Kirby: System API endpoint leaks license data and installed version to authenticated users CWE-862 4.3 - 2026-05-09
CVE-2026-42069 Kirby: Read access to site, user and role information is not gated by permissions CWE-862 4.3 - 2026-05-09
CVE-2026-41325 Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection CWE-863 8.8AI High AI 2026-04-24
CVE-2026-40099 Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter CWE-863 6.5AI Medium AI 2026-04-24
CVE-2026-34587 Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering CWE-1336 6.5AI Medium AI 2026-04-24
CVE-2026-32870 Kirby has XML injection in its XML creator toolkit CWE-91 7.1AI High AI 2026-04-24
CVE-2026-21896 Kirby is missing permission checks in the content changes API CWE-863 4.3 - 2026-01-08
CVE-2025-65012 Kirby CMS has cross-site scripting (XSS) in the changes dialog CWE-79 4.6AI Medium AI 2025-11-18
CVE-2025-31493 Path traversal of collection names during file system lookup CWE-22 8.3AI High AI 2025-05-13
CVE-2025-30207 Kirby vulnerable to path traversal in the router for PHP's built-in server CWE-22 8.1AI High AI 2025-05-13
CVE-2025-30159 Kirby vulnerable to path traversal of snippet names in the `snippet()` helper CWE-22 7.1AI High AI 2025-05-13
CVE-2024-41964 Insufficient permission checks in the language settings in Kirby CMS CWE-863 8.1 High 2024-08-29
CVE-2024-27087 Kirby cross-site scripting (XSS) in the link field "Custom" type CWE-79 4.6 Medium 2024-02-26
CVE-2023-38492 Kirby vulnerable to denial of service from unlimited password lengths CWE-770 5.3 Medium 2023-07-27

All 43 known CVE vulnerabilities affecting kirby with full Chinese analysis, references, and POCs where available.