Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-42069
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by …
Kirby
4.9.0 / 5.4.0+
MEDIUM 6.5
CVE-2026-42137
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not…
Kirby
4.9.0 / 5.4.0+
HIGH 8.8
CVE-2026-41325
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…
Kirby
4.9.0 / 5.4.0+
HIGH 8.1
CVE-2026-34587
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to …
Kirby
4.9.0 / 5.4.0+
MEDIUM 6.5
CVE-2026-40099
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content…
Kirby
4.9.0 / 5.4.0+
HIGH 7.5
CVE-2026-32870
Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value …
Kirby
4.9.0 / 5.4.0+
MEDIUM 6.5
CVE-2026-29905
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image up…
Kirby
after 5.1.4
MEDIUM 5.7
CVE-2026-21896
Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This …
Kirby
5.2.2+
MEDIUM 5.4
CVE-2025-65012
Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any user…
Kirby
5.1.4+
CRITICAL 9.1
CVE-2025-31493
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use…
Kirby
3.9.8.3 / 3.10.1.2+
HIGH 7.5
CVE-2025-30207
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that us…
Kirby
3.9.8.3 / 3.10.1.2+
CRITICAL 9.1
CVE-2025-30159
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use…
Kirby
3.9.8.3 / 3.10.1.2+
HIGH 8.1
CVE-2024-41964
Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform …
Kirby
3.6.6.6 / 3.7.5.5+
MEDIUM 5.4
CVE-2024-27087
Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered lin…
Kirby
4.1.1+
MEDIUM 6.1
CVE-2024-26484
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scr…
Kirby
Patch available
HIGH 8.8
CVE-2024-26483
An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF f…
Kirby
3.6.6.5 / 3.7.5.4+
HIGH 7.1
CVE-2024-26482
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this repo…
Kirby
No fix yet
HIGH 7.5
CVE-2023-38492
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with…
Kirby
3.5.8.3 / 3.6.6.3+
MEDIUM 5.4
CVE-2023-38491
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that…
Kirby
3.5.8.3 / 3.6.6.3+
CRITICAL 10.0
CVE-2023-38490
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites tha…
Kirby
3.5.8.3 / 3.6.6.3+
HIGH 7.3
CVE-2023-38489
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with…
Kirby
3.5.8.3 / 3.6.6.3+
HIGH 8.8
CVE-2023-38488
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that…
Kirby
3.5.8.3 / 3.6.6.3+
CRITICAL 9.8
CVE-2017-20174
A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functiona…
Webmentions
2017-02-01+
MEDIUM 5.3
CVE-2022-39315
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby site…
Kirby
3.5.8.2 / 3.6.6.2+
MEDIUM 5.4
CVE-2022-36037
kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting …
Kirby
3.5.8.1+
MEDIUM 5.4
CVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
Kirby
No fix yet
MEDIUM 5.4
CVE-2022-35174
A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a craf…
Starterkit
No fix yet
MEDIUM 5.4
CVE-2021-41252
Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types,…
Kirby
after 3.5.7.1
MEDIUM 5.4
CVE-2021-41258
Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used …
Kirby
after 3.5.7.1
MEDIUM 5.4
CVE-2021-32735
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section fo…
Kirby
3.5.7+