Junglewise Threat Intelligence

CVE-2026-54002: Kirby CMS stored XSS in Dom sanitization component

CVE-2026-54002 · Severity: high · CVSS 4 · Published 2026-07-09

Technologies: Kirby. Vendors: Kirby.

Executive brief

Kirby, a content management system, is vulnerable to a security flaw where its built-in content filters fail to properly clean malicious code from certain text fields. An authenticated user could exploit this to inject harmful scripts into the website, potentially leading to the theft of user sessions or unauthorized actions when other users view the affected content. This issue primarily impacts sites using specific editor fields or custom plugins that process untrusted user input.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Kirby CMS within the Dom::sanitize() method and related Sane classes. The root cause is a failure to correctly sanitize malicious markup when it is injected as children of unknown HTML or XML tags, allowing the payload to bypass sanitization rules. The vulnerability affects the 'writer' and 'list' fields, as well as any custom implementation calling Dom::sanitize() or Sane::sanitize() with untrusted input. An authenticated attacker with permissions to edit content can inject malicious scripts that execute in the context of other users' browsers. The issue is resolved in versions 4.9.4 and 5.4.4.

Affected products

  • getkirby Kirby < 4.9.4, >= 5.0.0, < 5.4.4

Timeline

  • 2026-06-17: patched: Security releases 4.9.4 and 5.4.4 published.
  • 2026-07-09: advisory: NVD and GitHub advisory published.

References

Related threats