getkirby/cms Security Advisories for 5.4.3 (11)
-
[MEDIUM] Kirby: Access to image files outside of the site root via path traversal in the media handling
PKSA-cmzk-n5t6-2v3k CVE-2026-75592 GHSA-6j4c-mgqr-qv76
Affected version: >=5.0.0,<5.5.2|<4.9.5
Reported by:
GitHub -
[MEDIUM] Kirby: System path exposure from error messages in the REST API
PKSA-wq8z-fxnn-1fxz CVE-2026-69127 GHSA-rf2p-vh74-7vvh
Affected version: >=5.0.0,<5.5.2|<=4.9.4
Reported by:
GitHub -
[HIGH] Kirby: File upload permissions are not checked during processing of chunk data
PKSA-cxg1-n9gs-z2t6 CVE-2026-71415 GHSA-67mx-6wf2-92xp
Affected version: >=5.0.0,<5.5.2
Reported by:
GitHub -
[HIGH] Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
PKSA-n74d-ghht-18nt CVE-2026-75594 GHSA-9vx2-j98c-p72w
Affected version: >=5.0.0,<5.5.2|<=4.9.4
Reported by:
GitHub -
[HIGH] Kirby: `pages.access` permission is not checked in the `site/find` REST API route
PKSA-jpkc-34xj-4vfy CVE-2026-54005 GHSA-r3w8-2c5r-h9j9
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub -
[MEDIUM] Kirby: Access to files of top-level drafts is not protected by permissions
PKSA-6sq2-11dh-hkdq CVE-2026-54004 GHSA-89cp-7p28-jffg
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub -
[CRITICAL] Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
PKSA-h8zr-vfb5-1d5r CVE-2026-54003 GHSA-whxw-24jc-cwmv
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub -
[HIGH] Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
PKSA-wps5-gfv8-mm6f CVE-2026-54002 GHSA-wr9h-4r83-f4v6
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub -
[MEDIUM] Kirby: Request header injection in `Http\Remote`
PKSA-k11s-611y-v46q CVE-2026-50188 GHSA-4v4h-m2qq-ppgw
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub -
[HIGH] Kirby: Self cross-site scripting (self-XSS) in the writer field
PKSA-hnr2-vddk-p4gy CVE-2026-49276 GHSA-rhj6-r49h-5932
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub -
[MEDIUM] Kirby: `pages.access` permission is not checked in the pages picker for parent pages
PKSA-4ys7-5twb-r3bn CVE-2026-49274 GHSA-23q2-54qv-rq5x
Affected version: >=5.0.0-alpha.1,<=5.4.3|<=4.9.3
Reported by:
GitHub