getkirby/cms vulnerabilities
CVEs whose affected-version data names the getkirby/cms package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-75592MediumKirby is an open-source content management system
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Ki…
CVE-2026-75594HighKirby is an open-source content management system
Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated pare…
CVE-2026-71415HighKirby is an open-source content management system
Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Ap…
CVE-2026-69127MediumKirby is an open-source content management system
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauth…
CVE-2026-49274MediumKirby: `pages.access` permission is not checked in the pages picker for parent pages
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
CVE-2026-49276HighKirby: Self cross-site scripting (self-XSS) in the writer field
Kirby: Self cross-site scripting (self-XSS) in the writer field
CVE-2026-50188MediumKirby: Request header injection in `Http\Remote`
Kirby: Request header injection in `Http\Remote`
CVE-2026-54002HighKirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
CVE-2026-54004MediumKirby: Access to files of top-level drafts is not protected by permissions
Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-54003CriticalKirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
CVE-2026-54005HighKirby: `pages.access` permission is not checked in the `site/find` REST API route
Kirby: `pages.access` permission is not checked in the `site/find` REST API route