Kirby
cpe:2.3:a:getkirby:kirby:*:*:*:*:*:*:*
- <= 4.9.0
- >= 5.0.0, <= 5.4.0
A cross-site scripting (XSS) vulnerability has been identified in Kirby, an open-source content management system, affecting versions prior to 4.9.1 and 5.4.1. The issue arises in the list field, which stores content as HTML. Unlike other field types, HTML special characters in the list field cannot be escaped without losing formatting. This vulnerability allows attackers to inject malicious HTML that is saved unsanitized and executed on the site frontend, impacting visitors and logged-in users.
Exploitation of this vulnerability allows for persistent cross-site scripting, where injected JavaScript is executed automatically in the browsers of site visitors and logged-in users.
Users can update to Kirby versions 4.9.1 or 5.4.1 to address this vulnerability. Instructions for updating Kirby can be found in the Kirby documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.