getkirby/cms Security Advisories for 5.4.0 (6)
-
[HIGH] Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
PKSA-d956-rcc1-9n2f CVE-2026-45368 GHSA-qvjf-922g-pj44
Affected version: >=5.0.0,<=5.4.0|<=4.9.0
Reported by:
GitHub -
[MEDIUM] Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
PKSA-q7k8-c5gf-pkgc CVE-2026-45334 GHSA-39vq-49qm-r2mc
Affected version: >=5.0.0,<=5.4.0|<=4.9.0
Reported by:
GitHub -
[HIGH] Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
PKSA-82wy-dsmt-xgpc CVE-2026-44177 GHSA-9hx7-c53c-v6x8
Affected version: >=5.3.0,<=5.4.0
Reported by:
GitHub -
[MEDIUM] Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
PKSA-ycvm-k4m4-tr9m CVE-2026-44176 GHSA-2xw4-v2wx-hqq9
Affected version: >=5.0.0,<=5.4.0|<=4.9.0
Reported by:
GitHub -
[HIGH] Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
PKSA-g7d2-4qf5-mg45 CVE-2026-44175 GHSA-5fhx-9q32-q257
Affected version: >=5.0.0,<=5.4.0|<=4.9.0
Reported by:
GitHub -
[HIGH] Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
PKSA-hhnz-p4k9-sfyd CVE-2026-44174 GHSA-86rh-h242-j8xp
Affected version: >=5.0.0,<=5.4.0|<=4.9.0
Reported by:
GitHub