Executive brief
Kirby, a content management system, contains a security flaw in how it handles list fields. An attacker with basic editing permissions can bypass the standard administrative interface to save malicious code that will then run in the browsers of other site visitors. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Kirby CMS versions prior to 4.9.1 and 5.4.1. The 'list' field and 'list' block store content as raw HTML to preserve formatting, but sanitization was previously only enforced client-side within the Panel UI. An authenticated attacker with update permissions can bypass the Panel and send malicious HTML directly to Kirby's REST API. Because the server failed to sanitize this input on save, the malicious markup is stored in the content files and executed when rendered on the site frontend. The issue is resolved by implementing server-side HTML sanitization for list fields.
Affected products
- getkirby Kirby CMS < 4.9.1, >= 5.0.0, < 5.4.1
Timeline
- 2026-05-19: patched: Fixed in versions 4.9.1 and 5.4.1
- 2026-07-16: advisory: CVE-2026-44175 published