CVE-2026-45368: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in getkirby kirby
Kirby CMS versions prior to 4.9.1 and 5.4.1 contain a cross-site scripting (XSS) vulnerability in URL handling for KirbyTags and image blocks. Malicious URLs using schemes like javascript://, vbscript:, data:, livescript:, mocha:, and jar: can bypass existing protections and lead to script execution. This affects multiple first-party renderers that output anchor tags from user-supplied content. The issue is fixed in versions 4.9.1 and 5.4.1.
AI Analysis
Technical Summary
The vulnerability in Kirby CMS arises from improper neutralization of input during web page generation (CWE-79). Specifically, the URL methods for KirbyTags and image blocks did not adequately filter malicious URL schemes that can lead to cross-site scripting. While simple javascript: URLs were blocked by prepending a slash, more complex variants like javascript://x%0A bypassed this protection. Other schemes such as vbscript:, data:, livescript:, mocha:, and jar: are similarly exploitable. This affects four first-party Kirby renderers that produce <a href="..."> output from editor-supplied field values. The vulnerability is resolved in Kirby versions 4.9.1 and 5.4.1.
Potential Impact
Exploitation of this vulnerability allows an attacker to inject malicious scripts via crafted URLs in editor-supplied fields, potentially leading to cross-site scripting attacks. This can result in unauthorized script execution in the context of the affected website, impacting confidentiality and integrity of user interactions. The CVSS 4.0 score is 8.4 (high severity), indicating a significant risk with network attack vector, low attack complexity, and no privileges required but user interaction needed.
Mitigation Recommendations
This vulnerability has been fixed in Kirby CMS versions 4.9.1 and 5.4.1. Users should upgrade to at least these versions to remediate the issue. No official temporary fixes or workarounds are indicated. Patch status is confirmed by the vendor advisory stating the fix in these versions.
CVE-2026-45368: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in getkirby kirby
Description
Kirby CMS versions prior to 4.9.1 and 5.4.1 contain a cross-site scripting (XSS) vulnerability in URL handling for KirbyTags and image blocks. Malicious URLs using schemes like javascript://, vbscript:, data:, livescript:, mocha:, and jar: can bypass existing protections and lead to script execution. This affects multiple first-party renderers that output anchor tags from user-supplied content. The issue is fixed in versions 4.9.1 and 5.4.1.
CVSS v4.0
Score 8.4high
Affected software
pkg:github/getkirby/kirbyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Kirby CMS arises from improper neutralization of input during web page generation (CWE-79). Specifically, the URL methods for KirbyTags and image blocks did not adequately filter malicious URL schemes that can lead to cross-site scripting. While simple javascript: URLs were blocked by prepending a slash, more complex variants like javascript://x%0A bypassed this protection. Other schemes such as vbscript:, data:, livescript:, mocha:, and jar: are similarly exploitable. This affects four first-party Kirby renderers that produce <a href="..."> output from editor-supplied field values. The vulnerability is resolved in Kirby versions 4.9.1 and 5.4.1.
Potential Impact
Exploitation of this vulnerability allows an attacker to inject malicious scripts via crafted URLs in editor-supplied fields, potentially leading to cross-site scripting attacks. This can result in unauthorized script execution in the context of the affected website, impacting confidentiality and integrity of user interactions. The CVSS 4.0 score is 8.4 (high severity), indicating a significant risk with network attack vector, low attack complexity, and no privileges required but user interaction needed.
Mitigation Recommendations
This vulnerability has been fixed in Kirby CMS versions 4.9.1 and 5.4.1. Users should upgrade to at least these versions to remediate the issue. No official temporary fixes or workarounds are indicated. Patch status is confirmed by the vendor advisory stating the fix in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-12T00:51:29.085Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a59dfe668715ace439a8d69
Added to database: 07/17/2026, 07:55:18 UTC
Last enriched: 07/24/2026, 22:46:15 UTC
Last updated: 08/27/2026, 10:52:09 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.