CVE-2024-26483: Getkirby Kirby

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.

Affected products

  • Getkirby Kirby: before 3.6.6.5 (fixed in 3.6.6.5); from 3.7.0, before 3.7.5.4 (fixed in 3.7.5.4); from 3.8.0, before 3.8.4.3 (fixed in 3.8.4.3); from 3.9.0, before 3.9.8.1 (fixed in 3.9.8.1); from 4.0.0, up to and including 4.1.1; version 3.10.0 only

Published 2024-02-22. Last modified 2026-06-17.