CVE-2025-65012 is a medium-severity cross-site scripting (XSS) vulnerability affecting Kirby CMS versions 5.0.0 to 5.1.3. An authenticated attacker can manipulate page titles or usernames with malicious strings, which, when viewed by another authenticated Panel user in the "Changes" dialog, executes the malicious code. This requires user interaction and cannot be automated, with a CVSS score of 5.4. There is currently no known exploit intelligence, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.1.4CPE matchmatch criteria | cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.