Security Advisories for getkirby/cms in packagist
Moderate
about 1 month ago
Kirby: Access to image files outside of the site root via path traversal in the media handling
packagist
getkirby/cms
Moderate
about 1 month ago
Kirby: System path exposure from error messages in the REST API
packagist
getkirby/cms
High
about 1 month ago
Kirby: File upload permissions are not checked during processing of chunk data
packagist
getkirby/cms
High
about 1 month ago
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
packagist
getkirby/cms
High
4 months ago
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
packagist
getkirby/cms
Moderate
4 months ago
Kirby: Access to files of top-level drafts is not protected by permissions
packagist
getkirby/cms
Critical
4 months ago
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
packagist
getkirby/cms
High
4 months ago
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
packagist
getkirby/cms
High
4 months ago
Kirby: Self cross-site scripting (self-XSS) in the writer field
packagist
getkirby/cms
Moderate
4 months ago
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
packagist
getkirby/cms
High
4 months ago
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
packagist
getkirby/cms
Moderate
4 months ago
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions
packagist
getkirby/cms
High
4 months ago
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
packagist
getkirby/cms
Moderate
4 months ago
Kirby CMS's `pages.access` permission is not checked during rendering of page drafts
packagist
getkirby/cms
High
4 months ago
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
packagist
getkirby/cms
High
4 months ago
Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints
packagist
getkirby/cms
Moderate
5 months ago
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
packagist
getkirby/cms
Moderate
5 months ago
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
packagist
getkirby/cms
High
5 months ago
Kirby CMS's read access to site, user and role information is not gated by permissions
packagist
getkirby/cms
High
5 months ago
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
packagist
getkirby/cms
High
5 months ago
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
packagist
getkirby/cms
Moderate
6 months ago
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
packagist
getkirby/cms
High
6 months ago
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
packagist
getkirby/cms
Moderate
9 months ago
Kirby is missing permission checks in the content changes API
packagist
getkirby/cms
Moderate
11 months ago
Kirby CMS has cross-site scripting (XSS) in the changes dialog
packagist
getkirby/cms
Potential
Moderate
over 1 year ago
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
packagist
getkirby/kirby
Low
over 1 year ago
Kirby vulnerable to path traversal in the router for PHP's built-in server
packagist
getkirby/cms
Moderate
over 1 year ago
Kirby vulnerable to path traversal of collection names during file system lookup
packagist
getkirby/cms
High
about 2 years ago
Kirby has insufficient permission checks in the language settings
packagist
getkirby/cms
Moderate
over 2 years ago
Kirby vulnerable to Cross-site scripting (XSS) in the link field "Custom" type
packagist
getkirby/cms
Moderate
over 2 years ago
Kirby vulnerable to self cross-site scripting (self-XSS) in the URL field
packagist
getkirby/cms
Moderate
over 2 years ago
Kirby vulnerable to unrestricted file upload of user avatar images
packagist
getkirby/cms
High
about 3 years ago
Insufficient Session Expiration after a password change
packagist
getkirby/cms
Moderate
about 3 years ago
XML External Entity (XXE) vulnerability in the XML data handler
packagist
getkirby/cms
Moderate
about 3 years ago
Cross-site scripting (XSS) from MIME type auto-detection of uploaded files
packagist
getkirby/cms
Moderate
almost 4 years ago
Kirby CMS vulnerable to user enumeration in the brute force protection
packagist
getkirby/cms
Moderate
almost 4 years ago
Kirby CMS vulnerable to user enumeration in the code-based login and password reset forms
packagist
getkirby/cms
High
about 4 years ago
Cross-site scripting from content entered in the tags and multiselect fields
packagist
getkirby/cms
Moderate
about 4 years ago
Cross-site scripting from dynamic options in the multiselect field
packagist
getkirby/cms
Moderate
almost 5 years ago
Cross-site scripting (XSS) from image block content in the site frontend
packagist
getkirby/cms
Moderate
almost 5 years ago
Cross-site scripting (XSS) from writer field content in the site frontend
packagist
getkirby/cms
High
over 5 years ago
Cross-site scripting (XSS) from field and configuration text displayed in the Panel
packagist
getkirby/cms
High
over 5 years ago
Cross-site scripting (XSS) from unsanitized uploaded SVG files in Kirby
packagist
getkirby/cms
Moderate
over 5 years ago
Kirby .dev domains and some reverse proxy setups were treated as local
packagist
getkirby/cms, getkirby/panel
Moderate
almost 6 years ago
Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5
packagist
getkirby/cms, getkirby/panel