CVEs we hold for Getkirby
Records whose assigning authority named Getkirby as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-75594Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media…getkirby kirby
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlinggetkirby kirby
CVE-2026-71415Kirby: File upload permissions are not checked during processing of chunk datagetkirby kirby
CVE-2026-54005Kirby: `pages.access` permission is not checked in the `site/find` REST API routegetkirby kirby
CVE-2026-54004Kirby: Access to files of top-level drafts is not protected by permissionsgetkirby kirby
CVE-2026-54003Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` headergetkirby kirby
CVE-2026-54002Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`getkirby kirby
CVE-2026-49274Kirby: `pages.access` permission is not checked in the pages picker for parent pagesgetkirby kirby
CVE-2026-45368Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontendgetkirby kirby
CVE-2026-45334Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissionsgetkirby kirby
CVE-2026-44177Kirby: Pre-authentication path traversal and PHP file inclusion during user lookupgetkirby kirby
CVE-2026-44176Kirby: `pages.access` permission is not checked during rendering of page draftsgetkirby kirby
CVE-2026-44175Kirby: Cross-site scripting (XSS) from list field content in the site frontendgetkirby kirby
CVE-2026-44174Kirby: Arbitrary Method Call via REST API search and collection query endpointsgetkirby kirby
CVE-2026-42174Kirby: User avatar creation, replacement and deletion are not gated by user update permissionsgetkirby kirby
CVE-2026-42137Kirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes…getkirby kirby
CVE-2026-42069Kirby: Read access to site, user and role information is not gated by permissionsgetkirby kirby
CVE-2026-42051Kirby: System API endpoint leaks license data and installed version to authenticated usersgetkirby kirby
CVE-2026-41325Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injectiongetkirby kirby
CVE-2026-40099Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parametergetkirby kirby
CVE-2026-34587Kirby has Server-Side Template Injection (SSTI) via double template resolution in option renderinggetkirby kirby
CVE-2025-30207Kirby vulnerable to path traversal in the router for PHP's built-in servergetkirby kirby
CVE-2025-30159Kirby vulnerable to path traversal of snippet names in the `snippet()` helpergetkirby kirby
CVE-2023-38491Kirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded filesgetkirby kirby
CVE-2023-38489Kirby vulnerable to Insufficient Session Expiration after a password changegetkirby kirby
CVE-2023-38488Kirby vulnerable to field injection in the KirbyData text storage handlergetkirby kirby
CVE-2022-36037Cross-site scripting (XSS) from dynamic options in the multiselect field in Kirbygetkirby kirby
CVE-2021-41258Cross-site scripting (XSS) from image block content in the site frontendgetkirby kirby
CVE-2021-41252Cross-site scripting (XSS) from writer field content in the site frontendgetkirby kirby
CVE-2021-32735Cross-site scripting (XSS) from field and configuration text displayed in the Panelgetkirby kirby
46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.