Vulnerabilities in getkirby

46 results
Vexday analysis

Getkirby apresenta 42 vulnerabilidades catalogadas, com 21 divulgadas nos últimos 90 dias, indicando ritmo elevado de descobertas. Não há registros de exploração ativa em campo (KEV), mas a fraqueza dominante é injeção XSS (CWE-79), típica de aplicações web, com apenas 1 falha crítica mitigando o risco imediato.

CVE-2026-45368HIGHKirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontendEPSS 0.5%CVE-2021-32735HIGHCross-site scripting (XSS) from field and configuration text displayed in the PanelEPSS 0.5%CVE-2026-69127MEDIUMKirby: System path exposure from error messages in the REST APIEPSS 0.5%CVE-2026-41325HIGHKirby is vulnerable to authorization bypass during page, file and user creation via blueprint injectionEPSS 0.5%CVE-2026-54004MEDIUMKirby: Access to files of top-level drafts is not protected by permissionsEPSS 0.5%CVE-2026-44174HIGHKirby: Arbitrary Method Call via REST API search and collection query endpointsEPSS 0.5%CVE-2026-49274MEDIUMKirby: `pages.access` permission is not checked in the pages picker for parent pagesEPSS 0.5%CVE-2024-41964HIGHInsufficient permission checks in the language settings in Kirby CMSEPSS 0.5%CVE-2026-34587HIGHKirby has Server-Side Template Injection (SSTI) via double template resolution in option renderingEPSS 0.5%CVE-2026-32870MEDIUMKirby has XML injection in its XML creator toolkitEPSS 0.5%CVE-2026-50188MEDIUMKirby: Request header injection in `Http\Remote`EPSS 0.4%CVE-2026-49276HIGHKirby: Self cross-site scripting (self-XSS) in the writer fieldEPSS 0.4%CVE-2026-44175HIGHKirby: Cross-site scripting (XSS) from list field content in the site frontendEPSS 0.4%CVE-2026-54005HIGHKirby: `pages.access` permission is not checked in the `site/find` REST API routeEPSS 0.4%CVE-2026-71415HIGHKirby: File upload permissions are not checked during processing of chunk dataEPSS 0.4%CVE-2026-42137HIGHKirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialogEPSS 0.4%CVE-2026-42069HIGHKirby: Read access to site, user and role information is not gated by permissionsEPSS 0.4%CVE-2026-40099MEDIUMKirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameterEPSS 0.4%CVE-2022-39314MEDIUMUser enumeration in the code-based login and password reset formsEPSS 0.4%CVE-2026-45334MEDIUMKirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissionsEPSS 0.4%