PT-2026-43450 · Packagist+2 · Getkirby/Cms+1

CVE-2026-44175

·

Published

2026-05-26

·

Updated

2026-07-17

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kirby versions prior to 4.9.1 Kirby versions prior to 5.4.1
Description Kirby failed to securely sanitize the contents of the list field on save, leading to stored cross-site scripting (XSS). While sanitization was enforced client-side in the Panel, the server did not sanitize content upon saving. An authenticated user with update permissions could bypass the Panel and send malicious HTML directly to the API, storing unsanitized markup in the content file. This markup is then executed in the browsers of site visitors and logged-in users when rendered on the site frontend. This is an auto-firing stored XSS, meaning the script executes automatically when the page loads.
Recommendations Update Kirby to version 4.9.1 or later. Update Kirby to version 5.4.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44175
GHSA-5FHX-9Q32-Q257

Affected Products

Getkirby/Cms
Kirby