Technology · Packagist
getkirby/cms (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in getkirby/cms (Packagist): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-71415, was published on 31 August 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 0
- Exploited in the wild
- 0
About getkirby/cms (Packagist)
A file-based content management system.
Latest getkirby/cms (Packagist) vulnerabilities
- CVE-2026-71415: Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in…highCVSS 4EPSS 0.4%
- CVE-2026-44177: Kirby CMS path traversal and PHP file inclusion in user lookuphighCVSS 4EPSS 1.8%
- CVE-2026-29905: Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image UploadlowCVSS 3.1EPSS 0.6%
- CVE-2026-21896: Kirby is missing permission checks in the content changes APImediumCVSS 4EPSS 0.2%
- CVE-2025-65012: Kirby CMS has cross-site scripting (XSS) in the changes dialogmediumCVSS 4EPSS 0.2%
- CVE-2024-27087: Kirby vulnerable to Cross-site scripting (XSS) in the link field "Custom" typelowCVSS 3.1EPSS 0.4%
- Duplicate Advisory: Unrestricted file upload of user avatar imagesinfo
- CVE-2024-26482: Withdrawn Advisory: Kirby CMS HTML injection vulnerabilitylowCVSS 3.1EPSS 0.3%
- Duplicate Advisory: Kirby vulnerable to self cross-site scripting (self-XSS) in the URL fieldlowCVSS 3.1
- CVE-2022-36037: Cross-site scripting from dynamic options in the multiselect fieldlowCVSS 3.1EPSS 0.9%
- CVE-2018-14520: Kirby CMS 2.5.12 Cross-site ScriptinglowCVSS 3.1EPSS 0.7%
- CVE-2018-14519: Kirby CMS 2.5.12 Cross-site Request ForgerylowCVSS 3.1EPSS 0.5%
- CVE-2021-41258: Cross-site scripting (XSS) from image block content in the site frontendlowCVSS 3.1EPSS 0.8%
- CVE-2021-41252: Cross-site scripting (XSS) from writer field content in the site frontendlowCVSS 3.1EPSS 0.9%
- CVE-2021-32735: Cross-site scripting (XSS) from field and configuration text displayed in the PanellowCVSS 3.1EPSS 0.5%
- CVE-2021-29460: Cross-site scripting (XSS) from unsanitized uploaded SVG files in KirbylowCVSS 3.1EPSS 3.2%
- CVE-2020-26253: Kirby .dev domains and some reverse proxy setups were treated as locallowCVSS 3.1EPSS 0.6%
- CVE-2020-26255: Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5lowCVSS 3.1EPSS 1.5%
Most severe getkirby/cms (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44177: Kirby CMS path traversal and PHP file inclusion in user lookuphighCVSS 4EPSS 1.8%
- CVE-2026-71415: Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in…highCVSS 4EPSS 0.4%
- CVE-2026-21896: Kirby is missing permission checks in the content changes APImediumCVSS 4EPSS 0.2%
- CVE-2025-65012: Kirby CMS has cross-site scripting (XSS) in the changes dialogmediumCVSS 4EPSS 0.2%
- CVE-2021-29460: Cross-site scripting (XSS) from unsanitized uploaded SVG files in KirbylowCVSS 3.1EPSS 3.2%
- CVE-2020-26255: Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5lowCVSS 3.1EPSS 1.5%
- CVE-2021-41252: Cross-site scripting (XSS) from writer field content in the site frontendlowCVSS 3.1EPSS 0.9%
- CVE-2022-36037: Cross-site scripting from dynamic options in the multiselect fieldlowCVSS 3.1EPSS 0.9%
- CVE-2021-41258: Cross-site scripting (XSS) from image block content in the site frontendlowCVSS 3.1EPSS 0.8%
- CVE-2018-14520: Kirby CMS 2.5.12 Cross-site ScriptinglowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/getkirby-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "getkirby/cms (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/getkirby-cms, 28 September 2026.