vciy

CVEs we hold for Getkirby

Records whose assigning authority named Getkirby as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-75594Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media…getkirby kirby
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlinggetkirby kirby
CVE-2026-71415Kirby: File upload permissions are not checked during processing of chunk datagetkirby kirby
CVE-2026-69127Kirby: System path exposure from error messages in the REST APIgetkirby kirby
CVE-2026-54005Kirby: `pages.access` permission is not checked in the `site/find` REST API routegetkirby kirby
CVE-2026-54004Kirby: Access to files of top-level drafts is not protected by permissionsgetkirby kirby
CVE-2026-54003Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` headergetkirby kirby
CVE-2026-54002Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`getkirby kirby
CVE-2026-50188Kirby: Request header injection in `Http\Remote`getkirby kirby
CVE-2026-49276Kirby: Self cross-site scripting (self-XSS) in the writer fieldgetkirby kirby
CVE-2026-49274Kirby: `pages.access` permission is not checked in the pages picker for parent pagesgetkirby kirby
CVE-2026-45368Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontendgetkirby kirby
CVE-2026-45334Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissionsgetkirby kirby
CVE-2026-44177Kirby: Pre-authentication path traversal and PHP file inclusion during user lookupgetkirby kirby
CVE-2026-44176Kirby: `pages.access` permission is not checked during rendering of page draftsgetkirby kirby
CVE-2026-44175Kirby: Cross-site scripting (XSS) from list field content in the site frontendgetkirby kirby
CVE-2026-44174Kirby: Arbitrary Method Call via REST API search and collection query endpointsgetkirby kirby
CVE-2026-42174Kirby: User avatar creation, replacement and deletion are not gated by user update permissionsgetkirby kirby
CVE-2026-42137Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes…getkirby kirby
CVE-2026-42069Kirby: Read access to site, user and role information is not gated by permissionsgetkirby kirby
CVE-2026-42051Kirby: System API endpoint leaks license data and installed version to authenticated usersgetkirby kirby
CVE-2026-41325Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injectiongetkirby kirby
CVE-2026-40099Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parametergetkirby kirby
CVE-2026-34587Kirby has Server-Side Template Injection (SSTI) via double template resolution in option renderinggetkirby kirby
CVE-2026-32870Kirby has XML injection in its XML creator toolkitgetkirby kirby
CVE-2026-21896Kirby is missing permission checks in the content changes APIgetkirby kirby
CVE-2025-65012Kirby CMS has cross-site scripting (XSS) in the changes dialoggetkirby kirby
CVE-2025-31493Path traversal of collection names during file system lookupgetkirby kirby
CVE-2025-30207Kirby vulnerable to path traversal in the router for PHP's built-in servergetkirby kirby
CVE-2025-30159Kirby vulnerable to path traversal of snippet names in the `snippet()` helpergetkirby kirby
CVE-2024-41964Insufficient permission checks in the language settings in Kirby CMSgetkirby kirby
CVE-2024-27087Kirby cross-site scripting (XSS) in the link field "Custom" typegetkirby kirby
CVE-2023-38492Kirby vulnerable to denial of service from unlimited password lengthsgetkirby kirby
CVE-2023-38491Kirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded filesgetkirby kirby
CVE-2023-38490Kirby XML External Entity (XXE) vulnerability in the XML data handlergetkirby kirby
CVE-2023-38489Kirby vulnerable to Insufficient Session Expiration after a password changegetkirby kirby
CVE-2023-38488Kirby vulnerable to field injection in the KirbyData text storage handlergetkirby kirby
CVE-2022-39315Kirby CMS vulnerable to user enumeration in the brute force protectiongetkirby kirby
CVE-2022-39314User enumeration in the code-based login and password reset formsgetkirby kirby
CVE-2022-36037Cross-site scripting (XSS) from dynamic options in the multiselect field in Kirbygetkirby kirby
CVE-2021-41258Cross-site scripting (XSS) from image block content in the site frontendgetkirby kirby
CVE-2021-41252Cross-site scripting (XSS) from writer field content in the site frontendgetkirby kirby
CVE-2021-32735Cross-site scripting (XSS) from field and configuration text displayed in the Panelgetkirby kirby
CVE-2021-29460Cross-site scripting (XSS) from unsanitized uploaded SVG filesgetkirby kirby
CVE-2020-26255PHP Phar archives could be uploaded and executed in Kirbygetkirby kirby
CVE-2020-26253.dev domains treated as local in Kirbygetkirby kirby

46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.