CVE-2026-49276
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a s
CVSS
—
Sin CVSS
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 9 jul 2026 · Última mod.: 10 jul 2026 · CWE-83
0.3%EPSS · 30 días0.3%
2026-07-102026-07-21
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4.