Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kirby MEDIUM 6.5
CVE-2026-42069

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by …

Fix: 4.9.0 / 5.4.0+
Fix from $1,600 2026-05-09
Kirby MEDIUM 6.5
CVE-2026-42137

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not…

Fix: 4.9.0 / 5.4.0+
Fix from $1,600 2026-05-09
Kirby HIGH 8.8
CVE-2026-41325

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…

Fix: 4.9.0 / 5.4.0+
Fix from $1,950 2026-04-24
Kirby HIGH 8.1
CVE-2026-34587

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to …

Fix: 4.9.0 / 5.4.0+
Fix from $1,950 2026-04-24
Kirby MEDIUM 6.5
CVE-2026-40099

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…

Fix: 4.9.0 / 5.4.0+
Fix from $1,600 2026-04-24
Kirby HIGH 7.5
CVE-2026-32870

Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value …

Fix: 4.9.0 / 5.4.0+
Fix from $1,950 2026-04-24
Kirby MEDIUM 6.5
CVE-2026-29905

Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image up…

Fix: after 5.1.4
Fix from $1,600 2026-03-26
Kirby MEDIUM 5.7
CVE-2026-21896

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This …

Fix: 5.2.2+
Fix from $1,600 2026-01-08
Kirby MEDIUM 5.4
CVE-2025-65012

Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any user…

Fix: 5.1.4+
Fix from $1,600 2025-11-18
Kirby CRITICAL 9.1
CVE-2025-31493

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use…

Fix: 3.9.8.3 / 3.10.1.2+
Fix from $2,300 2025-05-13
Kirby HIGH 7.5
CVE-2025-30207

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that us…

Fix: 3.9.8.3 / 3.10.1.2+
Fix from $1,950 2025-05-13
Kirby CRITICAL 9.1
CVE-2025-30159

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use…

Fix: 3.9.8.3 / 3.10.1.2+
Fix from $2,300 2025-05-13
Kirby HIGH 8.1
CVE-2024-41964

Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform …

Fix: 3.6.6.6 / 3.7.5.5+
Fix from $1,950 2024-08-29
Kirby MEDIUM 5.4
CVE-2024-27087

Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered lin…

Fix: 4.1.1+
Fix from $1,600 2024-02-26
Kirby MEDIUM 6.1
CVE-2024-26484

A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scr…

Patch available
Fix from $1,600 2024-02-22
Kirby HIGH 8.8
CVE-2024-26483

An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF f…

Fix: 3.6.6.5 / 3.7.5.4+
Fix from $1,950 2024-02-22
Kirby HIGH 7.1
CVE-2024-26482

An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this repo…

No fix yet
Fix from $1,950 2024-02-22
Kirby HIGH 7.5
CVE-2023-38492

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $1,950 2023-07-27
Kirby MEDIUM 5.4
CVE-2023-38491

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $1,600 2023-07-27
Kirby CRITICAL 10.0
CVE-2023-38490

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites tha…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $2,300 2023-07-27
Kirby HIGH 7.3
CVE-2023-38489

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $1,950 2023-07-27
Kirby HIGH 8.8
CVE-2023-38488

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $1,950 2023-07-27
Webmentions CRITICAL 9.8
CVE-2017-20174

A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functiona…

Fix: 2017-02-01+
Fix from $2,300 2023-01-19
Kirby MEDIUM 5.3
CVE-2022-39315

Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby site…

Fix: 3.5.8.2 / 3.6.6.2+
Fix from $1,600 2022-10-25
Kirby MEDIUM 5.4
CVE-2022-36037

kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting …

Fix: 3.5.8.1+
Fix from $1,600 2022-08-29
Kirby MEDIUM 5.4
CVE-2018-14520

An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.

No fix yet
Fix from $1,600 2022-08-24
Starterkit MEDIUM 5.4
CVE-2022-35174

A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a craf…

No fix yet
Fix from $1,600 2022-08-18
Kirby MEDIUM 5.4
CVE-2021-41252

Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types,…

Fix: after 3.5.7.1
Fix from $1,600 2021-11-16
Kirby MEDIUM 5.4
CVE-2021-41258

Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used …

Fix: after 3.5.7.1
Fix from $1,600 2021-11-16
Kirby MEDIUM 5.4
CVE-2021-32735

Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section fo…

Fix: 3.5.7+
Fix from $1,600 2021-07-02