Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getkirby — Vulnerabilities & Security Advisories 46

Browse all 46 CVE security advisories affecting getkirby. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetKirby is a flat-file CMS designed for web developers, utilizing PHP and YAML to manage content without a database. Its architecture, while simplifying deployment, has historically exposed it to significant security risks, resulting in twenty-five recorded CVEs. The most prevalent vulnerability classes involve Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation in file handling and template rendering processes. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative access. A notable incident involved a critical RCE vulnerability in the panel’s file upload functionality, which permitted attackers to execute arbitrary code on the server. These issues highlight the challenges of maintaining security in flat-file systems where traditional database protections are absent, necessitating rigorous code auditing and strict access controls to mitigate the inherent risks associated with its design philosophy.

Found 46 results / 46 Clear Filters
Top products by getkirby: kirby
CVE ID Title CVSS Severity Published
CVE-2024-41964 Insufficient permission checks in the language settings in Kirby CMS — kirby CWE-863 8.1 High 2024-08-29
CVE-2024-27087 Kirby cross-site scripting (XSS) in the link field "Custom" type — kirby CWE-79 4.6 Medium 2024-02-26
CVE-2023-38492 Kirby vulnerable to denial of service from unlimited password lengths — kirby CWE-770 5.3 Medium 2023-07-27
CVE-2023-38491 Kirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded files — kirby CWE-79 5.7 Medium 2023-07-27
CVE-2023-38490 Kirby XML External Entity (XXE) vulnerability in the XML data handler — kirby CWE-611 6.8 Medium 2023-07-27
CVE-2023-38489 Kirby vulnerable to Insufficient Session Expiration after a password change — kirby CWE-613 7.3 High 2023-07-27
CVE-2023-38488 Kirby vulnerable to field injection in the KirbyData text storage handler — kirby CWE-140 7.1 High 2023-07-27
CVE-2022-39315 Kirby CMS vulnerable to user enumeration in the brute force protection — kirby CWE-204 6.5 Medium 2022-10-25
CVE-2022-39314 User enumeration in the code-based login and password reset forms — kirby CWE-307 5.3 - 2022-10-24
CVE-2022-36037 Cross-site scripting (XSS) from dynamic options in the multiselect field in Kirby — kirby CWE-79 5.9 Medium 2022-08-29
CVE-2021-41258 Cross-site scripting (XSS) from image block content in the site frontend — kirby CWE-79 7.3 High 2021-11-16
CVE-2021-41252 Cross-site scripting (XSS) from writer field content in the site frontend — kirby CWE-79 7.3 High 2021-11-16
CVE-2021-32735 Cross-site scripting (XSS) from field and configuration text displayed in the Panel — kirby CWE-80 7.1 High 2021-07-02
CVE-2021-29460 Cross-site scripting (XSS) from unsanitized uploaded SVG files — kirby CWE-79 7.6 High 2021-04-27
CVE-2020-26255 PHP Phar archives could be uploaded and executed in Kirby — kirby CWE-434 6.8 Medium 2020-12-08
CVE-2020-26253 .dev domains treated as local in Kirby — kirby CWE-346 6.8 Medium 2020-12-08

This page lists every published CVE security advisory associated with getkirby. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.