Getkirby is a modestly represented but distinctly positioned flat-file and headless content management system whose vulnerability profile, despite a narrow product footprint, carries material risk due to its recurring weaknesses in request handling and authorization. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity across the core Kirby platform, its administrative Panel, and related components. The exposure concentrates in weakness classes that reflect the system's role as a content management interface—cross-site scripting and authorization failures (including missing and incorrect access controls) recur prominently, alongside path-traversal conditions that exploit inadequate filesystem boundary enforcement in file-handling and plugin contexts. Defenders deploying Kirby in production should prioritize administrative Panel access control and input-handling configurations, as flaws in these areas propagate to content-editing workflows and publishing capabilities. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getkirby over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38490CRITICAL Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e | Jul 27, 2023 | 10.0 | 31 | NO | NO |
CVE-2017-20174CRITICAL A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to | Jan 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-41325HIGH Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permi | Apr 24, 2026 | 8.8 | 29 | NO | NO |
CVE-2021-29460MEDIUM Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file | Apr 27, 2021 | 5.4 | 29 | NO | YES |
CVE-2017-16807MEDIUM A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has | Nov 13, 2017 | 5.4 | 29 | NO | YES |
CVE-2026-42069MEDIUM Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has bee | May 9, 2026 | 6.5 | 28 | NO | NO |
CVE-2026-42137MEDIUM Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Pa | May 9, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-34587HIGH Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to con | Apr 24, 2026 | 8.1 | 27 | NO | NO |
CVE-2020-26255CRITICAL Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file | Dec 8, 2020 | 9.1 | 27 | NO | NO |
CVE-2026-32870HIGH Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is | Apr 24, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getkirby.
Media articles that mention a CVE ID that affects a product developed by Getkirby — matched by CVE ID, not by vendor name.