Kirby Cross-Site Scripting Vulnerability in List Field

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Kirby, an open-source content management system, affecting versions prior to 4.9.1 and 5.4.1. The issue arises in the list field, which stores content as HTML. Unlike other field types, HTML special characters in the list field cannot be escaped without losing formatting. This vulnerability allows attackers to inject malicious HTML that is saved unsanitized and executed on the site frontend, impacting visitors and logged-in users.

Impact

Exploitation of this vulnerability allows for persistent cross-site scripting, where injected JavaScript is executed automatically in the browsers of site visitors and logged-in users.

Remediation

Users can update to Kirby versions 4.9.1 or 5.4.1 to address this vulnerability. Instructions for updating Kirby can be found in the Kirby documentation.

Added: Jul 16, 2026, 11:00 PM
Updated: Jul 16, 2026, 11:00 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
5.2
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.