Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.46% | — | Getkirby Kirby | 24/4/2026 | 17/6/2026 | Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a second time but allowed to pass through. However, prior to versions 4.9.0 and 5.4.0, it was possible to trick this check… | |
| Analizada | Media (6.5) | 0.57% | — | Getkirby Kirby | 26/3/2026 | 17/6/2026 | Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file for metadata or… | |
| Analizada | Media (5.8) | 0.23% | — | Getkirby Kirby | 8/1/2026 | 17/6/2026 | Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by disabling the… | |
| Analizada | Media (5.1) | 0.18% | — | Getkirby Kirby | 18/11/2025 | 17/6/2026 | Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any user to a malicious string. Then they could modify any content field of the same model without saving, making the model a candidate for display in the "Changes" dialog. If… | |
| Analizada | Media (6.3) | 0.57% | — | Getkirby Kirby | 13/5/2025 | 17/6/2026 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends on request or user data). Sites that… | |
| Analizada | Baja (2.3) | 0.56% | — | Getkirby Kirby | 13/5/2025 | 17/6/2026 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such as Apache, nginx or Caddy) are not… | |
| Analizada | Media (6.3) | 0.68% | — | Getkirby Kirby | 13/5/2025 | 17/6/2026 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet name that depends on request or user data). Sites that only use fixed… | |
| Analizada | Alta (8.1) | 0.48% | — | Getkirby Kirby | 29/8/2024 | 17/6/2026 | Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users of that role can only perform permitted actions. Permissions for creating and deleting languages have already existed and could be configured, but were not enforced by Kirby's frontend or backend… | |
| Analizada | Media (5.4) | 0.35% | — | Getkirby Kirby | 26/2/2024 | 17/6/2026 | Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link to the relevant URL format. It also includes a "Custom" link type for advanced use cases that don't fit any of the pre-defined link formats. As the "Custom" link type… | |
| Analizada | Media (6.1) | 0.43% | — | Getkirby Kirby | 22/2/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any version of Kirby CMS. The only effect… | |
| Analizada | Alta (8.8) | 0.97% | — | Getkirby Kirby | 22/2/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file. | |
| Analizada | Alta (7.1) | 0.32% | — | Getkirby Kirby | 22/2/2024 | 17/6/2026 | An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization such that the reporter's mentioned "injecting malicious… | |
| Analizada | Media (4.7) | 0.40% | — | Getkirby Kirby | 22/2/2024 | 17/6/2026 | Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Getkirby Kirby | 27/7/2023 | 17/6/2026 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). The real-world impact of this vulnerability is limited, however we still recommend to update to… | |
| Modificada | Media (5.4) | 0.62% | — | Getkirby Kirby | 27/7/2023 | 17/6/2026 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to upload an arbitrary file to the content folder. Kirby sites… | |
| Modificada | Crítica (10) | 1.7% | 💥 PoC | Getkirby Kirby | 27/7/2023 | 17/6/2026 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in site or plugin code. The Kirby core does not use any of the affected… | |
| Modificada | Alta (7.3) | 0.81% | — | Getkirby Kirby | 27/7/2023 | 17/6/2026 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a Kirby user is logged in on a device or browser that is shared with… | |
| Modificada | Alta (8.8) | 0.92% | — | Getkirby Kirby | 27/7/2023 | 17/6/2026 | Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to update a Kirby content file (e.g. via a contact or comment… | |
| Modificada | Crítica (9.8) | 0.79% | — | Getkirby Webmentions | 19/1/2023 | 17/6/2026 | A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The… | |
| Modificada | Media (5.3) | 0.66% | — | Getkirby Kirby | 25/10/2022 | 17/6/2026 | Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only be exploited for targeted attacks because the attack does not scale to brute… | |
| Modificada | Baja (3.7) | 0.39% | — | Getkirby Kirby | 24/10/2022 | 17/6/2026 | Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth method with the `auth.methods` option or… | |
| Modificada | Media (5.4) | 0.90% | — | Getkirby Kirby | 29/8/2022 | 17/6/2026 | kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting (XSS) is a type of vulnerability that allows execution of any kind of JavaScript code inside the Panel session of the same or other users. In the Panel, a harmful script… | |
| Modificada | Media (5.4) | 0.70% | — | Getkirby Kirby | 24/8/2022 | 17/6/2026 | An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages. | |
| Modificada | Media (4.3) | 0.49% | — | Getkirby Kirby | 24/8/2022 | 5/7/2026 | An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page. | |
| Modificada | Media (5.4) | 0.68% | — | Getkirby Starterkit | 18/8/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field. |