VulnSea

getkirby/cms vulnerabilities

CVEs whose affected-version data names the getkirby/cms package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-75592Medium
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Ki…

Sunlitgetkirby · getkirby/cmsEPSS 0.46%via NVD
CVE-2026-75594High
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated pare…

Twilightgetkirby · getkirby/cmsEPSS 0.51%via NVD
CVE-2026-71415High
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Ap…

Twilightgetkirby · getkirby/cmsEPSS 0.25%via NVD
CVE-2026-69127Medium
1mo ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauth…

Sunlitgetkirby · getkirby/cmsEPSS 0.29%via NVD
CVE-2026-49274Medium
3mo ago

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Sunlitgetkirby · getkirby/cmsEPSS 0.48%via GHSA
CVE-2026-49276High
3mo ago

Kirby: Self cross-site scripting (self-XSS) in the writer field

Kirby: Self cross-site scripting (self-XSS) in the writer field

Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
CVE-2026-50188Medium
3mo ago

Kirby: Request header injection in `Http\Remote`

Kirby: Request header injection in `Http\Remote`

Sunlitgetkirby · getkirby/cmsEPSS 0.44%via GHSA
CVE-2026-54002High
3mo ago

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Twilightgetkirby · getkirby/cmsEPSS 0.55%via GHSA
CVE-2026-54004Medium
3mo ago

Kirby: Access to files of top-level drafts is not protected by permissions

Kirby: Access to files of top-level drafts is not protected by permissions

Sunlitgetkirby · getkirby/cmsEPSS 0.50%via GHSA
CVE-2026-54003Critical
3mo ago

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Midnightgetkirby · getkirby/cmsEPSS 0.74%via GHSA
CVE-2026-54005High
3mo ago

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
getkirby/cms vulnerabilities (CVEs) · VulnSea