Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kirby — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in kirby, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the Kirby product, focusing on Common Weakness Enumeration (CWE) classifications and associated security tags. It collects detailed information regarding various security flaws identified within the Kirby content management system, covering vulnerabilities reported from 2015 through the present day. By analyzing these records, users can track vendor advisories related to specific versions of the software, understand the technical implications of distinct weakness classes such as improper input validation or insecure direct object references, and look up a product’s historical vulnerability trends to assess long-term security posture. The data includes both low-severity issues and critical flaws that have been publicly disclosed or patched, providing a comprehensive view of the product's attack surface over time. This aggregation serves as a reference point for security researchers, developers, and system administrators who need to evaluate the risk associated with deploying or maintaining Kirby instances. By presenting this information in a structured format, the page facilitates deeper analysis of how specific coding errors or configuration weaknesses have manifested across different releases, allowing stakeholders to make informed decisions about mitigation strategies and update schedules without relying on fragmented or incomplete data sources.

Vendor: getkirby

CVE ID Title CVSS Severity Published
CVE-2023-38491 Kirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded files CWE-79 5.7 Medium 2023-07-27
CVE-2023-38490 Kirby XML External Entity (XXE) vulnerability in the XML data handler CWE-611 6.8 Medium 2023-07-27
CVE-2023-38489 Kirby vulnerable to Insufficient Session Expiration after a password change CWE-613 7.3 High 2023-07-27
CVE-2023-38488 Kirby vulnerable to field injection in the KirbyData text storage handler CWE-140 7.1 High 2023-07-27
CVE-2022-39315 Kirby CMS vulnerable to user enumeration in the brute force protection CWE-204 6.5 Medium 2022-10-25
CVE-2022-39314 User enumeration in the code-based login and password reset forms CWE-307 5.3 - 2022-10-24
CVE-2022-36037 Cross-site scripting (XSS) from dynamic options in the multiselect field in Kirby CWE-79 5.9 Medium 2022-08-29
CVE-2021-41258 Cross-site scripting (XSS) from image block content in the site frontend CWE-79 7.3 High 2021-11-16
CVE-2021-41252 Cross-site scripting (XSS) from writer field content in the site frontend CWE-79 7.3 High 2021-11-16
CVE-2021-32735 Cross-site scripting (XSS) from field and configuration text displayed in the Panel CWE-80 7.1 High 2021-07-02
CVE-2021-29460 Cross-site scripting (XSS) from unsanitized uploaded SVG files CWE-79 7.6 High 2021-04-27
CVE-2020-26255 PHP Phar archives could be uploaded and executed in Kirby CWE-434 6.8 Medium 2020-12-08
CVE-2020-26253 .dev domains treated as local in Kirby CWE-346 6.8 Medium 2020-12-08

All 43 known CVE vulnerabilities affecting kirby with full Chinese analysis, references, and POCs where available.