Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Getkirby

First CVE: Nov 13, 2017Active for: 9 yearsTotal CVEs: 44
32.5
VTI Score
Medium

Getkirby is a modestly represented but distinctly positioned flat-file and headless content management system whose vulnerability profile, despite a narrow product footprint, carries material risk due to its recurring weaknesses in request handling and authorization. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity across the core Kirby platform, its administrative Panel, and related components. The exposure concentrates in weakness classes that reflect the system's role as a content management interface—cross-site scripting and authorization failures (including missing and incorrect access controls) recur prominently, alongside path-traversal conditions that exploit inadequate filesystem boundary enforcement in file-handling and plugin contexts. Defenders deploying Kirby in production should prioritize administrative Panel access control and input-handling configurations, as flaws in these areas propagate to content-editing workflows and publishing capabilities. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Getkirby over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2017
8 years ago
Most Recent CVE
May 9, 2026
76 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38490CRITICAL
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e
Jul 27, 202310.031NONO
CVE-2017-20174CRITICAL
A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to
Jan 19, 20239.830NONO
CVE-2026-41325HIGH
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permi
Apr 24, 20268.829NONO
CVE-2021-29460MEDIUM
Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file
Apr 27, 20215.429NOYES
CVE-2017-16807MEDIUM
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has
Nov 13, 20175.429NOYES
CVE-2026-42069MEDIUM
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has bee
May 9, 20266.528NONO
CVE-2026-42137MEDIUM
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Pa
May 9, 20266.527NONO
CVE-2026-34587HIGH
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to con
Apr 24, 20268.127NONO
CVE-2020-26255CRITICAL
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file
Dec 8, 20209.127NONO
CVE-2026-32870HIGH
Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is
Apr 24, 20267.525NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
64%
23%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.3%)
Network43 (97.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (93.2%)
High3 (6.8%)
Unknown0 (0.0%)
User Interaction
None23 (52.3%)
Unknown0 (0.0%)
Required21 (47.7%)
Privileges Required
Low26 (59.1%)
High3 (6.8%)
None15 (34.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Getkirby.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Getkirby — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Getkirby's Products

View all 3 CNAs →

Top CWEs