Vulnerabilidades en getkirby

46 resultados
Análisis Vexday

Getkirby apresenta 42 vulnerabilidades catalogadas, com 21 divulgadas nos últimos 90 dias, indicando ritmo elevado de descobertas. Não há registros de exploração ativa em campo (KEV), mas a fraqueza dominante é injeção XSS (CWE-79), típica de aplicações web, com apenas 1 falha crítica mitigando o risco imediato.

CVE-2021-29460HIGHCross-site scripting (XSS) from unsanitized uploaded SVG filesEPSS 3.2%CVE-2026-44177HIGHKirby: Pre-authentication path traversal and PHP file inclusion during user lookupEPSS 1.8%CVE-2023-38490MEDIUMKirby XML External Entity (XXE) vulnerability in the XML data handlerEPSS 1.7%CVE-2020-26255MEDIUMPHP Phar archives could be uploaded and executed in KirbyEPSS 1.5%CVE-2023-38492MEDIUMKirby vulnerable to denial of service from unlimited password lengthsEPSS 1.2%CVE-2021-41252HIGHCross-site scripting (XSS) from writer field content in the site frontendEPSS 0.9%CVE-2023-38488HIGHKirby vulnerable to field injection in the KirbyData text storage handlerEPSS 0.9%CVE-2022-36037MEDIUMCross-site scripting (XSS) from dynamic options in the multiselect field in KirbyEPSS 0.9%CVE-2023-38489HIGHKirby vulnerable to Insufficient Session Expiration after a password changeEPSS 0.8%CVE-2021-41258HIGHCross-site scripting (XSS) from image block content in the site frontendEPSS 0.8%CVE-2026-75594HIGHKirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlingEPSS 0.8%CVE-2026-54003CRITICALKirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` headerEPSS 0.7%CVE-2025-30159MEDIUMKirby vulnerable to path traversal of snippet names in the `snippet()` helperEPSS 0.7%CVE-2026-75592MEDIUMKirby: Access to image files outside of the site root via path traversal in the media handlingEPSS 0.7%CVE-2022-39315MEDIUMKirby CMS vulnerable to user enumeration in the brute force protectionEPSS 0.6%CVE-2023-38491MEDIUMKirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded filesEPSS 0.6%CVE-2020-26253MEDIUM.dev domains treated as local in KirbyEPSS 0.6%CVE-2025-31493MEDIUMPath traversal of collection names during file system lookupEPSS 0.6%CVE-2025-30207LOWKirby vulnerable to path traversal in the router for PHP's built-in serverEPSS 0.6%CVE-2026-54002HIGHKirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`EPSS 0.5%