Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-54002

34
FAUCET Score

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::sanitize(), Sane::sanitize(), Sane::Html::sanitize(), Sane::Svg::sanitize(), Sane::Xml::sanitize(), Sane::sanitizeFile(), or file sanitizeContents() with untrusted input allow malicious markup injected as children of an unknown HTML or XML tag to pass through Dom::sanitize() without being correctly sanitized, causing stored cross-site scripting. This issue is fixed in versions 4.9.4 and 5.4.4.

First published: Jul 9, 2026Last modified: Jul 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
GetkirbyKirby
< 4.9.4, >= 5.0.0, < 5.4.4CNA affected

CVSS Data

CVSS version used by this source: 4.0

8.5HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 42nd percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: getkirby/cmsFixed in: 4.9.4
composerpatch availablevia ghsa
Product: getkirby/cmsFixed in: 5.4.4

Vendor Advisories (1)

composerGHSA-wr9h-4r83-f4v6high

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Jun 18, 2026

References

github.com / getkirby/kirby/commit/0f0437b5128c910103cbc78fc34d94b2a3faef4c
github.com / getkirby/kirby/commit/7ad76cf9c7387462828e6ebfc8404e31b37829e9
github.com / getkirby/kirby/commit/9ec1873864441dbc06479ef7823da348ec7f2700
github.com / getkirby/kirby/commit/bb2562e16c754493a403b8df84c9883108871e4c
github.com / getkirby/kirby/releases/tag/4.9.4
github.com / getkirby/kirby/releases/tag/5.4.4
github.com / getkirby/kirby/security/advisories/GHSA-wr9h-4r83-f4v6