PT-2026-43450 · Packagist+2 · Getkirby/Cms+1
CVE-2026-44175
·
Published
2026-05-26
·
Updated
2026-07-17
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kirby versions prior to 4.9.1
Kirby versions prior to 5.4.1
Description
Kirby failed to securely sanitize the contents of the list field on save, leading to stored cross-site scripting (XSS). While sanitization was enforced client-side in the Panel, the server did not sanitize content upon saving. An authenticated user with update permissions could bypass the Panel and send malicious HTML directly to the API, storing unsanitized markup in the content file. This markup is then executed in the browsers of site visitors and logged-in users when rendered on the site frontend. This is an auto-firing stored XSS, meaning the script executes automatically when the page loads.
Recommendations
Update Kirby to version 4.9.1 or later.
Update Kirby to version 5.4.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getkirby/Cms
Kirby