CVE-2024-26481: Getkirby Kirby

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.

Affected products

  • Getkirby Kirby: before 3.6.6.5 (fixed in 3.6.6.5); from 3.7.0, before 3.7.5.4 (fixed in 3.7.5.4); from 3.8.0, before 3.8.4.3 (fixed in 3.8.4.3); from 3.9.0, before 3.9.8.1 (fixed in 3.9.8.1); from 4.0.0, up to and including 4.1.1; version 3.10.0 only

Published 2024-02-22. Last modified 2026-06-17.