Vulnerabilidades em getkirby
43 resultadosAnálise Vexday
Getkirby apresenta 42 vulnerabilidades catalogadas, com 21 divulgadas nos últimos 90 dias, indicando ritmo elevado de descobertas. Não há registros de exploração ativa em campo (KEV), mas a fraqueza dominante é injeção XSS (CWE-79), típica de aplicações web, com apenas 1 falha crítica mitigando o risco imediato.
CVE-2026-41325HIGHKirby is vulnerable to authorization bypass during page, file and user creation via blueprint injectionEPSS 0.4%CVE-2022-39314MEDIUMUser enumeration in the code-based login and password reset formsEPSS 0.4%CVE-2024-27087MEDIUMKirby cross-site scripting (XSS) in the link field "Custom" typeEPSS 0.3%CVE-2026-32870MEDIUMKirby has XML injection in its XML creator toolkitEPSS 0.3%CVE-2026-45368HIGHKirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontendEPSS 0.3%CVE-2026-34587HIGHKirby has Server-Side Template Injection (SSTI) via double template resolution in option renderingEPSS 0.3%CVE-2026-54004MEDIUMKirby: Access to files of top-level drafts is not protected by permissionsEPSS 0.3%CVE-2026-42137HIGHKirby: `pages.access/list` and `files.access/list` permissions are not consistently checked in the REST API and changes dialogEPSS 0.3%CVE-2026-69127MEDIUMKirby: System path exposure from error messages in the REST APIEPSS 0.3%CVE-2026-50188MEDIUMKirby: Request header injection in `Http\Remote`EPSS 0.3%CVE-2026-49276HIGHKirby: Self cross-site scripting (self-XSS) in the writer fieldEPSS 0.3%CVE-2026-44174HIGHKirby: Arbitrary Method Call via REST API search and collection query endpointsEPSS 0.3%CVE-2026-40099MEDIUMKirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameterEPSS 0.3%CVE-2026-49274MEDIUMKirby: `pages.access` permission is not checked in the pages picker for parent pagesEPSS 0.3%CVE-2026-54005HIGHKirby: `pages.access` permission is not checked in the `site/find` REST API routeEPSS 0.3%CVE-2026-44175HIGHKirby: Cross-site scripting (XSS) from list field content in the site frontendEPSS 0.3%CVE-2026-42174MEDIUMKirby: User avatar creation, replacement and deletion are not gated by user update permissionsEPSS 0.2%CVE-2026-42069HIGHKirby: Read access to site, user and role information is not gated by permissionsEPSS 0.2%CVE-2026-44176MEDIUMKirby: `pages.access` permission is not checked during rendering of page draftsEPSS 0.2%CVE-2026-45334MEDIUMKirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissionsEPSS 0.2%