📦 Kirby

by Getkirby

🔍 What is Kirby?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-31493

CRITICAL CVSS 9.1 May 13, 2025

This is a path traversal vulnerability in Kirby CMS that allows attackers to access and execute arbitrary files on the server when dynamic collection names are used. It affects Kirby sites using the c...

CVE-2025-30159

CRITICAL CVSS 9.1 May 13, 2025

This is a path traversal vulnerability in Kirby CMS that allows attackers to read and execute arbitrary files on the server when dynamic snippet names are used. It affects Kirby sites using the snippe...

CVE-2024-41964

HIGH CVSS 8.1 Aug 29, 2024

This vulnerability in Kirby CMS allows attackers with Panel access to manipulate language definitions despite permission restrictions. Users with restricted roles could update existing language defini...

CVE-2021-41258

HIGH CVSS 7.3 Nov 16, 2021

This CVE describes a stored cross-site scripting (XSS) vulnerability in Kirby CMS's image block functionality. Authenticated attackers can inject malicious HTML into image source, alt, and link fields...

CVE-2021-32735

HIGH CVSS 7.1 Jul 2, 2021

This vulnerability allows cross-site scripting (XSS) attacks in Kirby CMS Panel's ListItem component. Authenticated Panel users can escalate privileges by exploiting admin sessions, while visitors wit...

CVE-2026-21896

MEDIUM CVSS 5.7 Jan 8, 2026

This vulnerability allows users with restricted permissions to bypass intended write restrictions in Kirby CMS. Attackers with authenticated access can modify site content even when their role is conf...

CVE-2025-65012

MEDIUM CVSS 5.4 Nov 18, 2025

This is a stored cross-site scripting (XSS) vulnerability in Kirby CMS where attackers with Panel access can inject malicious code into page titles or usernames. When another authenticated user views ...