getkirby/cms
Kirby's core application folder
Activity
- Latest release
- 1mo ago
- Total releases
- 288
- Cadence
- ~6 days
- Last 12 months
- 30
Reach
- Stars
- 1.5k
Details
- License
- custom
- First release
- Jan 15, 2019
| Version | Released | |
|---|---|---|
5.5.3
patch
|
5.5.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.5.2
patch
| ||
4.9.5
patch
|
4.9.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.5.1
patch
4 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev | ||
6.0.0-alpha.3
pre
|
6.0.0-alpha.3
pre
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
5.5.0
minor
4 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev | ||
5.4.4
patch
4 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev |
5.4.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.9.4
patch
3 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev |
4.9.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.4.3
patch
11 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
5.4.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.9.3
patch
10 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
4.9.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.4.2
patch
11 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
5.4.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.9.2
patch
10 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
4.9.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.4.1
patch
11 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
5.4.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.9.1
patch
10 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
4.9.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.4.0
minor
17 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44177
GHSA-9hx7-c53c-v6x8
May 26, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites on Kirby 5.3.0-5.4.0 and is independent from setup conditions and authentication. This vulnerability is of high severity for all Kirby sites. IntroductionPath traversal is a type of attack that allows to access arbitrary filesystem paths. By using special elements such as PHP file inclusion is a type of attack that allows to load and execute PHP files on the server that are not intended for direct inclusion. Depending on the logic inside the PHP files, this can lead to disclosure of sensitive information or unintended, malicious actions. Affected componentsKirby's This applies to the authentication API (accessible to unauthenticated requests), the users API (accessible to authenticated users only) as well as to other places that use ImpactIn affected releases, Kirby did not correctly validate the provided user ID, causing a path traversal vulnerability. This vulnerability results in the following impact:
PatchesThe problem has been patched in Kirby 5.4.1. Please update to this or a later version to fix the vulnerability. In the mentioned release, Kirby has added additional checks to the user lookup that ensure that the provided user ID only contains valid characters and that the resulting path to the account directory is contained in the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev |
5.4.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.9.0
minor
15 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev |
4.9.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.3
patch
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44177
GHSA-9hx7-c53c-v6x8
May 26, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites on Kirby 5.3.0-5.4.0 and is independent from setup conditions and authentication. This vulnerability is of high severity for all Kirby sites. IntroductionPath traversal is a type of attack that allows to access arbitrary filesystem paths. By using special elements such as PHP file inclusion is a type of attack that allows to load and execute PHP files on the server that are not intended for direct inclusion. Depending on the logic inside the PHP files, this can lead to disclosure of sensitive information or unintended, malicious actions. Affected componentsKirby's This applies to the authentication API (accessible to unauthenticated requests), the users API (accessible to authenticated users only) as well as to other places that use ImpactIn affected releases, Kirby did not correctly validate the provided user ID, causing a path traversal vulnerability. This vulnerability results in the following impact:
PatchesThe problem has been patched in Kirby 5.4.1. Please update to this or a later version to fix the vulnerability. In the mentioned release, Kirby has added additional checks to the user lookup that ensure that the provided user ID only contains valid characters and that the resulting path to the account directory is contained in the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev |
5.3.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.2
patch
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44177
GHSA-9hx7-c53c-v6x8
May 26, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites on Kirby 5.3.0-5.4.0 and is independent from setup conditions and authentication. This vulnerability is of high severity for all Kirby sites. IntroductionPath traversal is a type of attack that allows to access arbitrary filesystem paths. By using special elements such as PHP file inclusion is a type of attack that allows to load and execute PHP files on the server that are not intended for direct inclusion. Depending on the logic inside the PHP files, this can lead to disclosure of sensitive information or unintended, malicious actions. Affected componentsKirby's This applies to the authentication API (accessible to unauthenticated requests), the users API (accessible to authenticated users only) as well as to other places that use ImpactIn affected releases, Kirby did not correctly validate the provided user ID, causing a path traversal vulnerability. This vulnerability results in the following impact:
PatchesThe problem has been patched in Kirby 5.4.1. Please update to this or a later version to fix the vulnerability. In the mentioned release, Kirby has added additional checks to the user lookup that ensure that the provided user ID only contains valid characters and that the resulting path to the account directory is contained in the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev | ||
5.3.1
patch
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44177
GHSA-9hx7-c53c-v6x8
May 26, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites on Kirby 5.3.0-5.4.0 and is independent from setup conditions and authentication. This vulnerability is of high severity for all Kirby sites. IntroductionPath traversal is a type of attack that allows to access arbitrary filesystem paths. By using special elements such as PHP file inclusion is a type of attack that allows to load and execute PHP files on the server that are not intended for direct inclusion. Depending on the logic inside the PHP files, this can lead to disclosure of sensitive information or unintended, malicious actions. Affected componentsKirby's This applies to the authentication API (accessible to unauthenticated requests), the users API (accessible to authenticated users only) as well as to other places that use ImpactIn affected releases, Kirby did not correctly validate the provided user ID, causing a path traversal vulnerability. This vulnerability results in the following impact:
PatchesThe problem has been patched in Kirby 5.4.1. Please update to this or a later version to fix the vulnerability. In the mentioned release, Kirby has added additional checks to the user lookup that ensure that the provided user ID only contains valid characters and that the resulting path to the account directory is contained in the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev |
5.3.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.0
minor
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44177
GHSA-9hx7-c53c-v6x8
May 26, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites on Kirby 5.3.0-5.4.0 and is independent from setup conditions and authentication. This vulnerability is of high severity for all Kirby sites. IntroductionPath traversal is a type of attack that allows to access arbitrary filesystem paths. By using special elements such as PHP file inclusion is a type of attack that allows to load and execute PHP files on the server that are not intended for direct inclusion. Depending on the logic inside the PHP files, this can lead to disclosure of sensitive information or unintended, malicious actions. Affected componentsKirby's This applies to the authentication API (accessible to unauthenticated requests), the users API (accessible to authenticated users only) as well as to other places that use ImpactIn affected releases, Kirby did not correctly validate the provided user ID, causing a path traversal vulnerability. This vulnerability results in the following impact:
PatchesThe problem has been patched in Kirby 5.4.1. Please update to this or a later version to fix the vulnerability. In the mentioned release, Kirby has added additional checks to the user lookup that ensure that the provided user ID only contains valid characters and that the resulting path to the account directory is contained in the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev | ||
6.0.0-alpha.2
pre
|
6.0.0-alpha.2
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.3.0-rc.1
pre
24 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev | ||
5.2.3
patch
24 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev | ||
5.2.2
patch
24 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev |
5.2.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.1
patch
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
5.2.0
minor
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
6.0.0-alpha.1
pre
|
6.0.0-alpha.1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.2.0-rc.1
pre
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev |
5.2.0-rc.1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.1.4
patch
25 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev |
5.1.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.1.3
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev |
5.1.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.1.2
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev | ||
5.1.1
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev | ||
5.1.0
minor
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev | ||
5.1.0-rc.1
pre
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev |
5.1.0-rc.1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.4
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev | ||
5.0.3
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev |
5.0.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.2
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev | ||
5.0.1
patch
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev | ||
5.0.0
major
26 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-71415
GHSA-67mx-6wf2-92xp
Aug 31, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have access to the REST API ( It was possible to fill up the temporary directory for chunked uploads with unfinished chunks even as a user without any upload permission. This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to upload files. The vulnerability can only be exploited by authenticated users. It was not possible to bypass the actual permission checks for any files that end up in the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's REST API provides routes to upload files, specifically to create content files, replace existing content files and to create and replace user avatars. Each upload route takes either full file upload requests or chunked upload requests that can be continued in subsequent requests. During a chunked upload, the incomplete state of the uploaded file is stored in a temporary directory until the last chunk completes the file. At this time, the final permission and business logic checks are performed before the complete file is moved to its final destination. ImpactIn affected releases, the chunk upload handler did not check for the user's file upload permissions before storing incomplete chunk data in the temporary directory. This allowed attackers without upload permissions to upload multiple large files in chunks. If the final chunk was never provided, Kirby would keep the incomplete files for 24 hours. This could cause attacker-controlled storage consumption until the temporary files were automatically cleaned up or manually removed, potentially preventing other users from uploading files, or site logic from storing data. PatchesThe problem has been patched in Kirby 5.5.2. Please update this or a later version to fix the vulnerability. In all of the mentioned releases, we have added preflight checks to the upload chunk processor that verify the relevant system permission before storing the chunk data in the temporary directory. CreditsThanks to @alcls01111 for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 16 more Show less
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-21896
GHSA-4j78-4xrm-cr2f
Jan 08, 2026
Kirby is missing permission checks in the content changes API
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the If developers haven't configured any user permissions that deviate from the default of allowing all actions, their site is not affected. IntroductionKirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for updating content have already existed and could be configured for each model type, but were not enforced by Kirby's API backend code during operations to the changes version. The changes version is the content version that contains unsaved changes of existing models (pages, users, files or the site). ImpactThe missing permission checks allowed attackers with Panel access to create or discard a changes version or update the content fields in an existing changes version. All of these actions could affect arbitrary models. This could cause the following impact:
PatchesThe problem has been patched in Kirby 5.2.2. Please update to this or a later version to fix the vulnerability. In the mentioned release, we have added checks for the model A future Kirby release will add separate CreditsThanks to Lukas Kleinschmidt (@lukaskleinschmidt) for responsibly reporting the identified issue. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
+ 2 more Show less
5.2.0-rc.1
5.2.1
Fixed in
5.2.2
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2025-65012
GHSA-84hf-8gh5-575j
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
Network
Low
Low
TL;DRThis vulnerability affects all Kirby 5 sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update page titles or usernames. The attack requires user interaction by another Panel user and cannot be automated. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. ImpactThe "Changes" dialog in the Panel displays all content models (pages, files, users) with changed content, i.e. with content that has not yet been published. Each changed model is listed with its preview image/icon and its title/name. Attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If another authenticated user subsequently opened the dialog in their Panel, the malicious code would be executed. PatchesThe problem has been patched in Kirby 5.1.4. Please update to this or a later version to fix the vulnerability. In the patch release, we have added the required escaping code to signal to the browser the intent of displaying plain text instead of code in the places where the model titles are rendered. Affected versions
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
Fixed in
5.1.4
References Updated Nov 20, 2025 · Source: OSV.dev |
5.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.0-rc.6
pre
7 CVEs
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0-rc.5
pre
7 CVEs
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0-rc.4
pre
7 CVEs
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
5.0.0-rc.4
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.0-rc.3
pre
7 CVEs
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev | ||
4.8.0
minor
23 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev |
4.8.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.0-rc.2
pre
7 CVEs
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev |
5.0.0-rc.2
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.0.0-rc.1
pre
7 CVEs
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev | ||
4.8.0-rc.1
pre
23 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev |
4.8.0-rc.1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.7.2
patch
23 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev | ||
4.7.1
patch
23 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev | ||
3.9.8.3
patch
23 CVEs
CVE-2026-75592
GHSA-6j4c-mgqr-qv76
Sep 02, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed in a way that their It was possible to create and access thumbnails from media files within such sibling directories that have a valid thumbnail configuration (JSON job file). This can affect staging sites, site backups or other internal sites. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the The media handler uses filesystem containment checks in several places that are supposed to prevent breakout of the ImpactIn affected releases, the containment checks were incomplete and did not cover the case of a sibling directory next to the containment directory that starts with the same prefix. E.g. a directory PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have hardened the containment helpers CreditsThanks to @0x1saac for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-69127
GHSA-rf2p-vh74-7vvh
Sep 01, 2026
Kirby: System path exposure from error messages in the REST API
Medium
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that have not disabled the REST API with the It was possible to trigger a PHP error in the API backend that would expose the full filesystem path of the Kirby installation on the server. This could be used to guess the default IntroductionAn information exposure occurs when system data or debugging information leaves the program through an output stream or logging function that makes it accessible to unauthorized parties. Using other weaknesses, an attacker could cause errors to occur; the response to these errors can reveal detailed system information, along with other impacts. An attacker can use messages that reveal technologies, operating systems, and product versions to tune the attack against known vulnerabilities in these technologies. A product may use diagnostic methods that provide significant implementation details such as stack traces as part of its error handling mechanism. Affected componentsKirby's REST API at The returned data for errors depends on the debugging mode. If the ImpactSome internal errors may contain sensitive information in the error message itself. This is often the case with PHP errors. In affected releases, the REST API error handler did not sanitize error messages for sensitive information. This exposed system information like the full source path to external API users, including users without authentication. This could be used to guess the default PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has hardened the API error handler to only expose full error messages for exceptions in the CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Sep 01, 2026 · Source: OSV.dev
CVE-2026-75594
GHSA-9vx2-j98c-p72w
Aug 31, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
Network
Low
None
None
TL;DRThis vulnerability affects all Kirby sites that are deployed to a server that allows requests for URLs with encoded slashes ( It was possible to create and access thumbnails from media files in arbitrary accessible directories on the server that have a valid thumbnail configuration (JSON job file). It was also possible to detect the presence of files with the This vulnerability is of high severity for affected sites. Server setups using Apache's default configuration or other servers that have been hardened against encoded slashes in URLs are not affected. IntroductionA path traversal (also known as directory traversal) vulnerability occurs when untrusted input is used to build a filesystem path without properly confining the result to an intended base directory. By injecting sequences such as Affected componentsKirby's media handler processes requests for files in the Each parent (such as a page) has its own media directory, which in turn contains the individual files. Kirby's media handler searches for the file within the parent's media directory. ImpactIn affected releases, Kirby did not prevent path traversal in the filenames that were searched within the parent directory. In affected server setups where the attacker can provide encoded slashes ( Because the response differs between existing and non-existing thumbnail configurations, attackers were able to tell whether an arbitrary JSON file exists on the server (addressed by a relative path from the media directory of an arbitrary existing parent, including a relative path that points outside of the site's PatchesThe problem has been patched in Kirby 4.9.5 and Kirby 5.5.2. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, CreditsThanks to Jorge González Milla (@Pig-Tail) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 254 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
4.9.4
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.4.4
5.5.0
5.5.1
Fixed in
4.9.5
5.5.2
References
Updated Aug 31, 2026 · Source: OSV.dev
CVE-2026-54005
GHSA-r3w8-2c5r-h9j9
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( It was possible to retrieve page information (including full content and metadata) for arbitrary pages via the This vulnerability is of high severity for affected sites. Your Kirby sites are not affected if you intend all users of your site to be able to access all pages of the site. The vulnerability can only be exploited by authenticated users that know or guess the IDs or UUIDs of pages. Write actions as well as access to draft pages are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsThe ImpactIn affected releases, Kirby did not check whether the queried pages were accessible to the currently authenticated user. This can lead to disclosure of sensitive information contained in inaccessible pages, including the confirmation of the existence of individual pages as well as disclosure of sensitive content fields stored in the pages. Linked children, siblings, or files were not affected by this vulnerability as they were already properly filtered by the appropriate Because the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added a filter ensuring that the CreditsThanks to Rizky Muhammad (@EvidentObscurity) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54004
GHSA-89cp-7p28-jffg
Jun 18, 2026
Kirby: Access to files of top-level drafts is not protected by permissions
Medium
Network
Low
None
None
TL;DRThis vulnerability affects Kirby 5 sites that have the It was possible to access clean file URLs of top-level drafts (e.g. Sites on Kirby 5 using the default configuration are not affected by this vulnerability (the IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsClean file redirects allow visitors to access files stored in the content folder via natural URLs such as Kirby 4.8.0 introduced the Files can be stored in pages. Pages can exist as drafts. In this draft state, the page preview is only accessible to users who are authenticated and authorized by the ImpactIn affected releases, the clean file redirects didn't take access logic for drafts into account. When a file stored in a draft page was accessed via its clean file URL, Kirby immediately redirected to the physical media URL without first checking whether the draft page was accessible to the user or visitor. This only affected top-level drafts (direct children of the site) because clean file URLs currently don't work for drafts that are nested under another page. The unauthorized clean file URL redirects for files in top-level drafts can lead to disclosure of sensitive information or data, e.g., ahead of the launch of a new product or post. A successful attack requires knowledge of the full path to the draft page and file, and therefore requires knowing the full clean file URL. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we added an authorization check to the route that redirects clean file URLs of drafts. This route now performs the same checks as the draft preview route, i.e., it only performs the redirect if a user is logged in and has the CreditsThanks to @adamyordan for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54003
GHSA-whxw-24jc-cwmv
Jun 18, 2026
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Critical
Network
Low
None
None
TL;DRThis vulnerability affects Kirby sites that have no configured user accounts and are running on publicly accessible servers behind a reverse proxy that sets the It was possible to install the Panel (= create the first admin user) in these setups even from remote IP addresses. This vulnerability is of critical severity for affected sites. Your site is not affected if any of the following apply:
IntroductionExternal Initialization is a type of vulnerability that allows attackers to initialize a system or configuration value without authentication. This can give untrusted actors access to the system or let them control its behavior. Affected componentsThe Kirby Panel and REST API are authenticated by local user accounts. If a Kirby installation does not yet have any users, it first needs to be installed. During the installation process, an initial admin user account is created. To protect against external initialization attacks that would allow untrusted actors to create an admin user for the Kirby installation, Kirby already checked whether the current request came from a local IP address. This allows installing the Panel in local development setups. Installation on remote servers was only supposed to be possible when the The ImpactIn affected releases, the This caused Kirby to falsely assume that an installation request was local and allowed creating an admin account even though the reverse proxy forwarded the request from an external IP address. Reverse proxies setting the PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we fixed the WorkaroundsSites on older Kirby versions (Kirby 3 starting at 3.7.0) can be protected with one of the following workarounds:
CreditsThanks to Peter Levashov (@petersevera) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-54002
GHSA-wr9h-4r83-f4v6
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
Network
Low
Low
TL;DRThis vulnerability affects Kirby sites and plugins that use the It was possible to inject malicious markup as children of an unknown HTML/XML tag, which would then be passed through This vulnerability is of high severity for affected sites. The default file upload protection is not affected, so sites that only validate uploaded files are not exposed to this vulnerability. The vulnerability can only be exploited by authenticated users. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows executing any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the maliciously injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsThe
Only the sanitization path (returning a cleaned document) is affected. The validation path is not affected by this vulnerability. Kirby's default upload protection performs validation, so malicious SVG or HTML uploads continue to be rejected. ImpactIn affected releases, An authenticated Panel user who can edit a PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Note that content that was passed through the sanitizer and stored as field content before the patch may contain malicious content that was not properly sanitized due to the vulnerable code. If you cannot rule out attackers under the authenticated users of a security-critical site, we advise reviewing the content for possible attacks or to re-sanitize all content of affected fields. CreditsThanks to Shafiq Aiman (@shafiqaimanx) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50188
GHSA-4v4h-m2qq-ppgw
Jun 18, 2026
Kirby: Request header injection in `Http\Remote`
Medium
Network
High
None
None
TL;DRThis vulnerability affects Kirby sites and plugins that use the By including newline characters in the value of the header, it was possible to inject a separate, independent header that was not intended to be set. A successful attack requires that an application or plugin forwards attacker-influenced input into a request header value. Sites that only send static, developer-defined headers are not affected. The attack does not target Panel users or site visitors directly; it targets the remote service that Kirby connects to. In Kirby's default configuration, the IntroductionHTTP header injection (also known as CRLF injection) is a type of vulnerability that allows an attacker to insert additional, attacker-controlled HTTP headers into a request or response. HTTP headers are separated by carriage-return and line-feed characters ( For outgoing requests, this means an attacker who controls part of a header value can add or override headers that the application did not intend to send. Depending on the remote service, this can be used to override security-relevant headers (such as Such vulnerabilities are relevant if untrusted input can reach the header values of an outgoing request – for example, a user-configurable API token, a forwarded tracking identifier, or any other value that originates from a request, form field, or content file. Affected componentsThe As the vulnerability is in the way ImpactIn affected releases, header values passed to The For example, a single
The receiving server parsed The vulnerability allows attackers to inject or override HTTP headers in outgoing requests, provided the affected application or plugin includes attacker-controlled data in a header value. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we now strip carriage-return and line-feed characters from header values before they are passed to the underlying request, preventing additional headers from being injected. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49276
GHSA-rhj6-r49h-5932
Jun 18, 2026
Kirby: Self cross-site scripting (self-XSS) in the writer field
High
Network
High
None
TL;DRThis vulnerability affects Kirby sites that use the writer field in any blueprint. It was possible to include a scripting link as the target of a link (or email link). This link target would then be clickable by the user who entered it. A successful attack commonly requires knowledge of the content structure by the attacker as well as social engineering of a user with access to the Panel. The attack cannot be automated. In Kirby's default configuration, the vulnerability is limited to self-XSS and cannot directly affect other users or visitors of the site. Panel plugins that are directly using the This vulnerability is of high severity for affected sites. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows attackers to execute any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script can, for example, trigger requests to Kirby's API with the permissions of the victim. Self cross-site scripting (self-XSS) typically involves a user inadvertently executing malicious code within their own context, often through social engineering techniques. This can occur when a user is tricked into pasting and executing malicious JavaScript code into the browser's developer console, address bar or form fields. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if you might have potential attackers in your group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on your site, other JavaScript-powered attacks are possible. Affected componentsThe As the vulnerability is in the writer mark components, it also affects all uses of the ImpactIn affected releases, the
The vulnerability allows attackers to inject malicious links into content. If the authenticated user clicked such a link before saving the content, the malicious script code would then be executed in their browser. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added more robust validation against dangerous URL schemes that are entered in the affected writer marks. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49274
GHSA-23q2-54qv-rq5x
Jun 18, 2026
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use the It was possible to confirm the existence of arbitrary pages and to retrieve the value of the title field of the pages found. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions on content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the backend logic for the page picker that is used in the ImpactIn affected releases, the backend logic did not validate that the user-provided parent page or site was accessible to the current user. This allowed authenticated attackers with knowledge of the full path to an existing page to confirm the existence of a particular page and to retrieve the value of the title field of that page. This could lead to the disclosure of sensitive information. PatchesThe problem has been patched in Kirby 4.9.4 and Kirby 5.4.4. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added a check verifying that the requested parent page or site is accessible to the current user before returning the picker data. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 266 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
4.9.1
4.9.2
4.9.3
5.0.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-beta.1
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-rc.1
5.0.0-rc.2
5.0.0-rc.3
5.0.0-rc.4
5.0.0-rc.5
5.0.0-rc.6
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
Fixed in
4.9.4
5.4.4
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45368
GHSA-qvjf-922g-pj44
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that allow the use of the This vulnerability is of high severity for affected sites. Kirby sites are not affected if none of the mentioned KirbyTags or block types are used, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in its templates). The Panel itself is unaffected and will not execute JavaScript that was injected into the IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if a consuming application might have potential attackers in its group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS exploits the Affected componentsKirby provides four first-party renderers that produce
ImpactIn affected releases, the underlying URL methods for these components did not filter out malicious URL values that resolve to script execution. While simple The vulnerability allows attackers to inject malicious links into content. The malicious links would then be rendered on the site frontend. If a site visitor or logged in user browsing the site would click such a link, the malicious script code would then be executed in the browser. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, a new
The HTML importer for blocks strips link targets with a dangerous scheme. Due to the hardening in these underlying URL methods, the affected KirbyTags and block no longer allow dangerous schemes in link targets. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45334
GHSA-39vq-49qm-r2mc
May 27, 2026
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that restrict the visibility of users for certain roles via the A Kirby site is not affected if all authenticated Panel users are permitted to access and list other users. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to gain access to information they are not intended to see. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions or access specific information in the CMS. These permissions are defined for each role in the user blueprint ( Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. ImpactIn affected releases, this lock information was returned without checking whether the requesting user had permission to access or list the locking user. This allowed a low-privilege authenticated Panel user, whose role was configured with The email address can allow to enumerate admin accounts, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In the mentioned releases, the lock information is now filtered based on the requesting user's permissions. The identity of the locking user is hidden when the requesting user does not have permission to access or list that user. CreditsKirby thanks Matteo Panzeri (@matte1782) for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44176
GHSA-2xw4-v2wx-hqq9
May 26, 2026
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access pages ( Kirby sites are not affected if they intend all users of the site to be able to access all page drafts of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. Affected componentsKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the This vulnerability affects the path resolver for the main CMS router. The resolver takes an input path from the requested URL and determines which model (page or file) should be rendered. When a path is requested that points to a page draft, the resolver checks that the request either contains a valid preview token or is authenticated by a valid user. ImpactIn affected releases, Kirby allowed page drafts to be rendered if any valid user was authenticated, even if that user did not have access to the specific page model. Authenticated attackers with knowledge of the full path to an existing page draft could then access the rendered frontend page. This could lead to the disclosure of sensitive information, e.g. ahead of the launch of a new product or post. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check that verifies that the requested page draft is accessible to the current user before rendering the draft template. CreditsKirby thank to @adrgs for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44175
GHSA-5fhx-9q32-q257
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
Network
Low
Low
TL;DRThis vulnerability affects all Kirby sites that use the list field or list block, when content is authored by users who may not be fully trusted. The attack requires an authenticated Panel user with update permission to any list field or list block. This vulnerability is of high severity for affected sites. Kirby sites are not affected if they don't use the list field (or blocks field with the list block) in any of their blueprints, or if every user who can edit content is fully trusted. The attack only surfaces in the site frontend (i.e. in the consuming project's templates). The Panel itself is unaffected and will not execute JavaScript that was injected into list field content. IntroductionCross-site scripting (XSS) is a type of vulnerability that allows to execute any kind of JavaScript code inside the site frontend or Panel session of the same or other users. In the Panel, a harmful script can for example trigger requests to Kirby's API with the permissions of the victim. In a stored XSS attack, the malicious payload is saved into the content data and has the potential to affect other users or site visitors. Such vulnerabilities are critical if applications might have potential attackers in their group of authenticated Panel users. They can escalate their privileges if they get access to the Panel session of an admin user. Depending on the site, other JavaScript-powered attacks are possible. A specific class of stored XSS is auto-firing, meaning the malicious injected JavaScript code is executed by the browser when the page loads without the victim having to perform a specific action. Affected componentsKirby's list field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. ImpactIn affected releases, Kirby did not securely sanitize the contents of list fields on save. This allowed attackers to inject malicious HTML code into the content file by sending it to Kirby's API directly without using the Panel. This malicious HTML code would then be displayed on the site frontend and executed in the browsers of site visitors and logged in users who are browsing the site. PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added HTML sanitization (like in the writer field) to the backend code that handles updates to the contents of list fields. CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44174
GHSA-86rh-h242-j8xp
May 26, 2026
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites and has a high real-world impact. IntroductionArbitrary method call is a type of arbitrary code execution. It is a vulnerability that allows attackers to run any commands or code of the attacker's choice on a target machine or in a target process. Depending on the set of accessible methods, this can lead to disclosure of sensitive information or to unintended and malicious write actions. Affected componentsKirby's data model is made up of model objects that are contained in collection objects. These collections can be queried with methods such as Kirby also provides endpoints in its REST API that allow to search through users or through children and files of the site or of a particular page. These endpoints allow the ImpactIn affected releases, Kirby did not validate the model attributes that were used in the collection queries. This allowed attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as PatchesThe problem has been patched in Kirby 4.9.1 and Kirby 5.4.1. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a blocklist of sensitive model methods that should not be called during collection operations and limited the query options for the affected endpoints to search and pagination. CreditsKirby thanks @mojamojam for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 244 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
4.9.0
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
5.4.0
Fixed in
4.9.1
5.4.1
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42051
GHSA-x68m-c7jf-2572
May 04, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the The installed Kirby version and license data can be used by malicious actors during reconnaissance when planning a separate attack. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have protected the version and license properties of the CreditsKirby thanks @HuajiHD and @0x-bala for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42174
GHSA-39cp-6679-8xv2
May 04, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to update user information ( Kirby sites are not affected if they intend all users of the site to be able to upload, replace or delete user avatars. The vulnerability can only be exploited by authenticated users. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby only checked the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added additional permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42069
GHSA-2h7v-4372-f6x2
May 04, 2026
Kirby CMS's read access to site, user and role information is not gated by permissions
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users. This vulnerability is of high severity for affected sites. Sites using Kirby are not affected if they intend all users of the site to be able to list and access the site model and all users and roles, including the content stored within these models. Write actions are not affected by this vulnerability as they were gated by permissions before. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( In affected releases, Kirby did not provide permission settings that control the access to the site model as well as to users and user roles. If the site developer disabled all permissions via the wildcard To be specific, the following permissions were missing in affected releases and have been added in the patches:
Access to role information such as the list of existing roles, their names and descriptions as well as their configured permissions were also not gated by user-based permissions. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added the missing permissions that are listed in the "Impact" section. The CreditsKirby thanks @HuajiHD for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 13, 2026 · Source: OSV.dev
CVE-2026-42137
GHSA-85x2-r8xv-ww8c
Apr 30, 2026
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to access or list pages or files ( This vulnerability is of high severity for affected sites. Consumers' Kirby sites are not affected if they intend all users to be able to access all pages and files of the site. The vulnerability can only be exploited by authenticated users. Write actions are not affected by this vulnerability. IntroductionMissing authorization allows authenticated users to perform actions they are not intended to have access to. The effects of missing authorization can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the In affected releases, Kirby did not consistently hide non-listable models (models for which the respective
PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have added permission checks for Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-41325
GHSA-6gqr-mx34-wh8r
Apr 24, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users of a particular role have no permission to create pages, files or users ( This vulnerability is of high severity for affected sites. Developers' Kirby sites are not affected if they intend all users of their site to be able to create pages, files and users. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( Kirby provides the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, we have updated the normalization code that is used during the creation of pages, files and users to include a filter for the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40099
GHSA-w942-j9r6-hr6r
Apr 23, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Medium
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites where users have the permission to create pages ( Users' Kirby sites are not affected if their use case does not consider the creation of published pages a malicious action. The vulnerability can only be exploited by authenticated users. IntroductionAn authorization bypass allows authenticated users to perform actions they should not be allowed to perform based on their configured permissions, thereby causing a privilege escalation. The effects of an authorization bypass can include unauthorized access to sensitive information as well as unauthorized changes to content or system information. ImpactKirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint ( For pages, Kirby provides the New pages are created as drafts by default and need to be published by changing the page status of an existing page draft. This is ensured when the page is created via the Kirby Panel. However the REST API allows to override the PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added a check to the page creation rules that ensures that users without the CreditsKirby thanks @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34587
GHSA-jcjw-58rv-c452
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
Network
Low
Low
None
TL;DRThis vulnerability affects all Kirby sites that use option fields ( This vulnerability is of high severity for affected sites. Users' Kirby sites are not affected if they are not using any of the mentioned fields or the IntroductionServer-Side Template Injection vulnerabilities (SSTI) occur when user input is embedded in a template in an unsafe manner and results in remote code execution on the server. Injected user input is wrongly treated as a template command instead of as a literal string of text. This allows attackers to query arbitrary information from the affected system or call arbitrary methods to perform actions. In a Kirby site this can be used to access protected site information, alter site content or break site behavior. ImpactKirby provides field types ( Static options can contain queries in the form However, dynamic options can often not be trusted. This is why the "options from query" and "options from API" modes are intended to resolve the option values and text strings based on queries not defined within the data source but within the blueprint. Unfortunately, the results of these trusted queries on untrusted source data are run through the query parser a second time in affected Kirby releases. Because of the double-resolution of dynamic option values and text strings, attackers could place malicious query templates such as PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has updated the CreditsKirby thanks to @offset for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-32870
GHSA-9wfj-c55w-j9qr
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Medium
Network
Low
None
None
TL;DRThis vulnerability only affects Kirby sites that use the If consumers use an affected method and cannot rule out input to these methods controlled by an attacker, Kirby strongly recommends that they update to a patch release. IntroductionXML strings contain structured data in tags and attributes. Depending on the used XML schema, this data can carry specific meaning that can lead to actions in other systems that parse and act on the XML data. Tags and attributes are detected based on their specific syntax, which includes characters such as XML injection is an attack on a system generating or parsing XML files. By injecting special characters into input data, XML output with a malicious meaning could be generated by a vulnerable system. ImpactKirby's The Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. PatchesThe problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. Please update to one of these or a later version to fix the vulnerability. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged CreditsKirby thanks to Patrick Falb (@dapatrese) at FORMER 03 for responsibly reporting the identified issue. Affected versions
3.0.0
3.0.1
3.0.1-rc.1
3.0.2
3.0.2-rc.1
3.0.3
3.0.3-rc.1
3.0.3-rc.2
3.0.3-rc.3
3.1.0
3.1.0-rc.1
3.1.1
+ 242 more Show less
3.1.2
3.1.2-rc.1
3.1.3
3.1.3-rc.1
3.1.4
3.1.4-rc.1
3.10.0
3.10.0.1
3.10.1
3.10.1.1
3.10.1.2
3.2.0
3.2.0-rc.1
3.2.0-rc.2
3.2.0-rc.3
3.2.0-rc.4
3.2.1
3.2.1-rc.1
3.2.2
3.2.3
3.2.3-rc.1
3.2.4
3.2.4-rc.1
3.2.5
3.2.5-rc.1
3.2.5-rc.2
3.3.0
3.3.0-rc.1
3.3.0-rc.2
3.3.0-rc.3
3.3.0-rc.4
3.3.0-rc.5
3.3.1
3.3.1-rc.1
3.3.2
3.3.2-rc.1
3.3.3
3.3.3-rc.1
3.3.4
3.3.4-rc.1
3.3.5
3.3.5-rc.1
3.3.6
3.4.0
3.4.0-rc.1
3.4.0-rc.2
3.4.0-rc.3
3.4.1
3.4.1-rc.1
3.4.2
3.4.3
3.4.3-rc.1
3.4.4
3.4.4-rc.1
3.4.5
3.5.0
3.5.0-rc.1
3.5.0-rc.2
3.5.0-rc.3
3.5.0-rc.4
3.5.0-rc.5
3.5.0-rc.6
3.5.0-rc.7
3.5.1
3.5.1-rc.1
3.5.2
3.5.2-rc.1
3.5.3
3.5.3.1
3.5.4
3.5.5
3.5.5-rc.1
3.5.6
3.5.6-rc.1
3.5.7
3.5.7-rc.1
3.5.7.1
3.5.8
3.5.8.1
3.5.8.2
3.5.8.3
3.5.8.4
3.6.0
3.6.0-alpha.1
3.6.0-alpha.2
3.6.0-alpha.3
3.6.0-alpha.4
3.6.0-beta.1
3.6.0-beta.2
3.6.0-beta.3
3.6.0-rc.1
3.6.0-rc.2
3.6.0-rc.3
3.6.0-rc.4
3.6.0-rc.5
3.6.1
3.6.1.1
3.6.2
3.6.2-rc.1
3.6.2-rc.2
3.6.2-rc.3
3.6.3
3.6.3-rc.1
3.6.3-rc.2
3.6.3.1
3.6.4
3.6.4-rc.1
3.6.5
3.6.5-rc.1
3.6.6
3.6.6-rc.1
3.6.6.1
3.6.6.2
3.6.6.3
3.6.6.4
3.6.6.5
3.6.6.6
3.7.0
3.7.0-rc.1
3.7.0-rc.2
3.7.0-rc.3
3.7.0.1
3.7.0.2
3.7.1
3.7.1-rc.1
3.7.2
3.7.2-rc.1
3.7.2.1
3.7.3
3.7.3-rc.1
3.7.4
3.7.4-rc.1
3.7.5
3.7.5.1
3.7.5.2
3.7.5.3
3.7.5.4
3.7.5.5
3.8.0
3.8.0-rc.1
3.8.0-rc.2
3.8.0-rc.3
3.8.1
3.8.1-rc.1
3.8.1.1
3.8.2
3.8.2-rc.1
3.8.3
3.8.3-rc.1
3.8.3-rc.2
3.8.4
3.8.4.1
3.8.4.2
3.8.4.3
3.8.4.4
3.9.0
3.9.0-rc.1
3.9.0-rc.2
3.9.1
3.9.1-rc.1
3.9.2
3.9.2-rc.1
3.9.3
3.9.3-rc.1
3.9.4
3.9.4-rc.1
3.9.5
3.9.5-rc.1
3.9.6
3.9.6-rc.1
3.9.6.1
3.9.7
3.9.7-rc.1
3.9.8
3.9.8-rc.1
3.9.8.1
3.9.8.2
3.9.8.3
4.0.0
4.0.0-alpha.1
4.0.0-alpha.2
4.0.0-alpha.3
4.0.0-alpha.4
4.0.0-alpha.5
4.0.0-alpha.6
4.0.0-alpha.7
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-rc.1
4.0.0-rc.2
4.0.0-rc.3
4.0.0-rc.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.0-rc.1
4.1.0-rc.2
4.1.0-rc.3
4.1.1
4.1.2
4.2.0
4.2.0-rc.1
4.3.0
4.3.0-rc.1
4.3.1
4.4.0
4.4.0-rc.1
4.4.1
4.5.0
4.5.0-rc.1
4.6.0
4.6.0-rc.1
4.6.1
4.7.0
4.7.0-rc.1
4.7.1
4.7.2
4.8.0
4.8.0-rc.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.0-rc.1
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.0-rc.1
5.2.1
5.2.2
5.2.3
5.3.0
5.3.0-rc.1
5.3.1
5.3.2
5.3.3
Fixed in
4.9.0
5.4.0
References Updated May 05, 2026 · Source: OSV.dev |
3.9.8.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|