Vulnerabilidades em getkirby
46 resultadosAnálise Vexday
Getkirby apresenta 42 vulnerabilidades catalogadas, com 21 divulgadas nos últimos 90 dias, indicando ritmo elevado de descobertas. Não há registros de exploração ativa em campo (KEV), mas a fraqueza dominante é injeção XSS (CWE-79), típica de aplicações web, com apenas 1 falha crítica mitigando o risco imediato.
CVE-2026-75594HIGHKirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlingEPSS 0.5%CVE-2026-54004MEDIUMKirby: Access to files of top-level drafts is not protected by permissionsEPSS 0.5%CVE-2026-44174HIGHKirby: Arbitrary Method Call via REST API search and collection query endpointsEPSS 0.5%CVE-2026-49274MEDIUMKirby: `pages.access` permission is not checked in the pages picker for parent pagesEPSS 0.5%CVE-2024-41964HIGHInsufficient permission checks in the language settings in Kirby CMSEPSS 0.5%CVE-2026-75592MEDIUMKirby: Access to image files outside of the site root via path traversal in the media handlingEPSS 0.5%CVE-2026-50188MEDIUMKirby: Request header injection in `Http\Remote`EPSS 0.4%CVE-2026-49276HIGHKirby: Self cross-site scripting (self-XSS) in the writer fieldEPSS 0.4%CVE-2026-44175HIGHKirby: Cross-site scripting (XSS) from list field content in the site frontendEPSS 0.4%CVE-2026-54005HIGHKirby: `pages.access` permission is not checked in the `site/find` REST API routeEPSS 0.4%CVE-2022-39314MEDIUMUser enumeration in the code-based login and password reset formsEPSS 0.4%CVE-2026-44176MEDIUMKirby: `pages.access` permission is not checked during rendering of page draftsEPSS 0.4%CVE-2026-45334MEDIUMKirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissionsEPSS 0.4%CVE-2026-41325HIGHKirby is vulnerable to authorization bypass during page, file and user creation via blueprint injectionEPSS 0.4%CVE-2024-27087MEDIUMKirby cross-site scripting (XSS) in the link field "Custom" typeEPSS 0.3%CVE-2026-32870MEDIUMKirby has XML injection in its XML creator toolkitEPSS 0.3%CVE-2026-34587HIGHKirby has Server-Side Template Injection (SSTI) via double template resolution in option renderingEPSS 0.3%CVE-2026-42137HIGHKirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialogEPSS 0.3%CVE-2026-69127MEDIUMKirby: System path exposure from error messages in the REST APIEPSS 0.3%CVE-2026-40099MEDIUMKirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameterEPSS 0.3%