Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getkirby — Vulnerabilities & Security Advisories 46

Browse all 46 CVE security advisories affecting getkirby. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetKirby is a flat-file CMS designed for web developers, utilizing PHP and YAML to manage content without a database. Its architecture, while simplifying deployment, has historically exposed it to significant security risks, resulting in twenty-five recorded CVEs. The most prevalent vulnerability classes involve Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation in file handling and template rendering processes. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative access. A notable incident involved a critical RCE vulnerability in the panel’s file upload functionality, which permitted attackers to execute arbitrary code on the server. These issues highlight the challenges of maintaining security in flat-file systems where traditional database protections are absent, necessitating rigorous code auditing and strict access controls to mitigate the inherent risks associated with its design philosophy.

Top products by getkirby: kirby
CVE ID Title CVSS Severity Published
CVE-2026-75594 Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling — kirby CWE-22 8.2 High 2026-08-31
CVE-2026-75592 Kirby: Access to image files outside of the site root via path traversal in the media handling — kirby CWE-22 6.9 Medium 2026-08-31
CVE-2026-71415 Kirby: File upload permissions are not checked during processing of chunk data — kirby CWE-862 7.1 High 2026-08-31
CVE-2026-69127 Kirby: System path exposure from error messages in the REST API — kirby CWE-497 6.9 Medium 2026-08-07
CVE-2026-45368 Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend — kirby CWE-79 - - 2026-07-16
CVE-2026-45334 Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions — kirby CWE-862 - - 2026-07-16
CVE-2026-44175 Kirby: Cross-site scripting (XSS) from list field content in the site frontend — kirby CWE-79 - - 2026-07-16
CVE-2026-44176 Kirby: `pages.access` permission is not checked during rendering of page drafts — kirby CWE-862 - - 2026-07-16
CVE-2026-44177 Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup — kirby CWE-22 - - 2026-07-16
CVE-2026-44174 Kirby: Arbitrary Method Call via REST API search and collection query endpoints — kirby CWE-470 - - 2026-07-16
CVE-2026-49276 Kirby: Self cross-site scripting (self-XSS) in the writer field — kirby CWE-83 - - 2026-07-09
CVE-2026-54005 Kirby: `pages.access` permission is not checked in the `site/find` REST API route — kirby CWE-862 - - 2026-07-09
CVE-2026-50188 Kirby: Request header injection in `Http\Remote` — kirby CWE-93 - - 2026-07-09
CVE-2026-54004 Kirby: Access to files of top-level drafts is not protected by permissions — kirby CWE-862 - - 2026-07-09
CVE-2026-49274 Kirby: `pages.access` permission is not checked in the pages picker for parent pages — kirby CWE-862 - - 2026-07-09
CVE-2026-54003 Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header — kirby CWE-454 - - 2026-07-09
CVE-2026-54002 Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()` — kirby CWE-79 - - 2026-07-09
CVE-2026-42174 Kirby: User avatar creation, replacement and deletion are not gated by user update permissions — kirby CWE-862 4.3 - 2026-05-09
CVE-2026-42137 Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialog — kirby CWE-862 8.2 - 2026-05-09
CVE-2026-42051 Kirby: System API endpoint leaks license data and installed version to authenticated users — kirby CWE-862 4.3 - 2026-05-09
CVE-2026-42069 Kirby: Read access to site, user and role information is not gated by permissions — kirby CWE-862 4.3 - 2026-05-09
CVE-2026-41325 Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection — kirby CWE-863 8.8AI High AI 2026-04-24
CVE-2026-40099 Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter — kirby CWE-863 6.5AI Medium AI 2026-04-24
CVE-2026-34587 Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering — kirby CWE-1336 6.5AI Medium AI 2026-04-24
CVE-2026-32870 Kirby has XML injection in its XML creator toolkit — kirby CWE-91 7.1AI High AI 2026-04-24
CVE-2026-21896 Kirby is missing permission checks in the content changes API — kirby CWE-863 4.3 - 2026-01-08
CVE-2025-65012 Kirby CMS has cross-site scripting (XSS) in the changes dialog — kirby CWE-79 4.6AI Medium AI 2025-11-18
CVE-2025-31493 Path traversal of collection names during file system lookup — kirby CWE-22 8.3AI High AI 2025-05-13
CVE-2025-30207 Kirby vulnerable to path traversal in the router for PHP's built-in server — kirby CWE-22 8.1AI High AI 2025-05-13
CVE-2025-30159 Kirby vulnerable to path traversal of snippet names in the `snippet()` helper — kirby CWE-22 7.1AI High AI 2025-05-13

This page lists every published CVE security advisory associated with getkirby. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.