<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Kirby (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/kirby.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kirby-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Kirby (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41325 – Kirby is an open-source content management system. Kirby's user permissions cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41325</guid>
    <pubDate>Fri, 24 Apr 2026 01:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41325</strong></p>
  <p>Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to customize the permissions for each target model in the model blueprints (such as in `site/blueprints/pages/...…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34587 – Kirby is an open-source content management system. Prior to versions 4.9.0 and 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34587</guid>
    <pubDate>Fri, 24 Apr 2026 01:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34587</strong></p>
  <p>Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined for each role in the user blueprint (`site/blueprints/users/...`). It is also possible to customize the permissions for each target model in the model blueprints (su…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32870 – Kirby is an open-source content management system. Kirby's `Xml::value()` method...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32870</guid>
    <pubDate>Fri, 24 Apr 2026 01:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32870</strong></p>
  <p>Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a second time but allowed to pass through. However, prior to versions 4.9.0 and 5.4.0, it was possible to trick this check into allowing values that only contained a valid `CDATA` block but also contained o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31493 – Kirby is an open-source content management system. A vulnerability in versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31493</guid>
    <pubDate>Tue, 13 May 2025 16:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31493</strong></p>
  <p>Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends on request or user data). Sites that only use fixed calls to the `collection()` helper/`$kirby->collection()` method (i…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30207 – Kirby is an open-source content management system. A vulnerability in versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30207</guid>
    <pubDate>Tue, 13 May 2025 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30207</strong></p>
  <p>Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such as Apache, nginx or Caddy) are not affected. A missing path traversal check allowed attackers to navigate all files on th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30159 – Kirby is an open-source content management system. A vulnerability in versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30159</guid>
    <pubDate>Tue, 13 May 2025 15:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30159</strong></p>
  <p>Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet name that depends on request or user data). Sites that only use fixed calls to the `snippet()` helper/`$kirby->snippet()` method (i.e. calls with a s…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41964 – Kirby is a CMS targeting designers and editors. Kirby allows to restrict the per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41964</guid>
    <pubDate>Thu, 29 Aug 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41964</strong></p>
  <p>Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and deleting languages have already existed and could be configured, but were not enforced by Kirby's frontend or backend code. A permission for updating existing languages has not existed before the patche…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26483 – An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26483</guid>
    <pubDate>Thu, 22 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26483</strong></p>
  <p>An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26482 – An HTML injection vulnerability exists in the Edit Content Layout module of Kirb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26482</guid>
    <pubDate>Thu, 22 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26482</strong></p>
  <p>An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization such that the reporter's mentioned "injecting malicious scripts" would not occur.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38489 – Kirby is a content management system. A vulnerability in versions prior to 3.5.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38489</guid>
    <pubDate>Thu, 27 Jul 2023 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38489</strong></p>
  <p>Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a Kirby user is logged in on a device or browser that is shared with potentially untrusted users or if an attacker already maliciously used a previous…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38488 – Kirby is a content management system. A vulnerability in versions prior to 3.5.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38488</guid>
    <pubDate>Thu, 27 Jul 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38488</strong></p>
  <p>Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update a Kirby content file (e.g. via a contact or comment form). Kirby sites are *not* affected if they don't allow write access for untrust…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-140</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41258 – Kirby is an open source file structured CMS. In affected versions Kirby's blocks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41258</guid>
    <pubDate>Tue, 16 Nov 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41258</strong></p>
  <p>Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used in block snippets to convert the blocks to HTML for use in your templates. We recommend to escape HTML special characters to protect against cross-site scripting (XSS) attacks. The default snippet for the image block unfortunately did not use our esc…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41252 – Kirby is an open source file structured CMS ### Impact Kirby's writer field stor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41252</guid>
    <pubDate>Tue, 16 Nov 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41252</strong></p>
  <p>Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. If the user is logged in to the Panel, a harmful script can for example trigger requests to Kirby's API with the…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32735 – Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32735</guid>
    <pubDate>Fri, 02 Jul 2021 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32735</strong></p>
  <p>Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their privileges if they get access to the Panel session of an admin user. Visitors without…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29460 – Kirby is an open source CMS. An editor with write access to the Kirby Panel can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29460</guid>
    <pubDate>Tue, 27 Apr 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29460</strong></p>
  <p>Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim opens that link in a browser where they are logged in to Kirby, the script will run and can for example trigger requests to Kirby's API with the permissi…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29460">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
