Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.81%—Getkirby Kirby16/11/202117/6/2026
Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used in block snippets to convert the blocks to HTML for use in your templates. We recommend to escape HTML special characters to protect against cross-site scripting (XSS)…
ModificadaMedia (5.4)0.93%—Getkirby Kirby16/11/202117/6/2026
Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would be lost. If the user is logged in to the…
ModificadaMedia (5.4)0.53%—Getkirby Kirby2/7/202117/6/2026
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their…
ModificadaMedia (5.4)3.2%💥 ExploitGetkirby Kirby27/4/202117/6/2026
Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim opens that link in a browser where they are logged in to Kirby, the…
ModificadaCrítica (9.1)1.5%—Getkirby KirbyGetkirby Panel8/12/202017/6/2026
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file and execute it on the server. This vulnerability is critical if you might have potential attackers in your group of authenticated Panel…
ModificadaMedia (5.9)0.57%—Getkirby KirbyGetkirby Panel8/12/202017/6/2026
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.3.6, and Kirby Panel before version 2.5.14 there is a vulnerability in which the admin panel may be accessed if hosted on a .dev domain. In order to protect new installations on public servers that don't have an admin account for the Panel yet, we block…
ModificadaMedia (5.4)0.68%—Getkirby Kirby13/5/201917/6/2026
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
ModificadaMedia (4.8)0.67%—Getkirby Kirby13/5/201917/6/2026
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
ModificadaMedia (4.8)0.56%—Getkirby Kirby28/12/201817/6/2026
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
ModificadaMedia (6.1)0.75%—Getkirby Kirby20/12/201817/6/2026
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
ModificadaMedia (5.4)0.57%—Getkirby Kirby4/12/201817/6/2026
panel/login in Kirby v2.5.12 allows XSS via a blog name.
ModificadaMedia (5.4)2.4%💥 ExploitGetkirby Panel13/11/201717/6/2026
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.
ModificadaMedia (6.5)1.3%—Bastian Allgeier Kirby20/11/201517/6/2026
Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension.
Orbitaley — Vulnerabilidades