Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2. Join the discussion | CVE Database V5 | 08/07/2026, 18:33:19 UTC Added: 08/07/2026, 18:56:59 UTC |
0 Kirby CMS versions prior to 4.9.1 and 5.4.1 contain a cross-site scripting (XSS) vulnerability in URL handling for KirbyTags and image blocks. Malicious URLs using schemes like javascript://, vbscript:, data:, livescript:, mocha:, and jar: can bypass existing protections and lead to script execution. This affects multiple first-party renderers that output anchor tags from user-supplied content. The issue is fixed in versions 4.9.1 and 5.4.1. Join the discussion | CVE Database V5 | 07/16/2026, 21:49:46 UTC Added: 07/17/2026, 07:55:18 UTC |
Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information without checking the requesting user's access permissions. Kirby's Panel includes a content-locking feature that records which user currently has a model open for editing. This lock prevents conflicting edits by multiple users and displays the locking user's identity in the Panel UI so other users know who to contact. Internally, the locking user's email address and identifier are included in every Panel view payload and in error responses returned when a user attempts to edit a model that is currently locked by another user. This allowed a low-privilege authenticated Panel user, whose role was configured with users.access: false or users.list: false, to learn the email address and identifier of any user who currently had a model open for editing in the Panel, including administrators and other higher-privilege users. Content locks are active for a configurable window (10 minutes by default). The email address can allow admin account enumeration, target phishing, and feed credential-stuffing attacks against the Kirby installation or other sites. The internal user ID can be cross-referenced with other endpoints once the requester has obtained a higher privilege through unrelated means. This issue has been fixed in versions 4.9.1 and 5.4.1. Join the discussion | CVE Database V5 | 07/16/2026, 21:42:51 UTC Added: 07/17/2026, 07:55:18 UTC |
0 Kirby CMS versions prior to 4.9.1 and 5.4.1 have a persistent cross-site scripting (XSS) vulnerability in the list field. The vulnerability arises because the list field stores formatted content as HTML without proper server-side sanitization on save. While client-side sanitization was enforced in the Panel, attackers could bypass it by sending malicious HTML directly to the API, resulting in stored unsanitized markup that executes in site visitors' and logged-in users' browsers. This issue has been fixed in versions 4.9.1 and 5.4.1. Join the discussion | CVE Database V5 | 07/16/2026, 21:36:06 UTC Added: 07/16/2026, 21:48:08 UTC |
Kirby CMS versions prior to 4.9.1 and 5.4.1 have a missing authorization check for the pages.access permission during page draft rendering. Authenticated users without proper access rights could view page drafts if they know the full path, potentially exposing sensitive unpublished content. This issue has been fixed in versions 4.9.1 and 5.4.1. Join the discussion | CVE Database V5 | 07/16/2026, 21:24:04 UTC Added: 07/16/2026, 21:48:08 UTC |
0 Kirby CMS versions 5.3.0 up to but not including 5.4.1 contain a path traversal vulnerability due to improper validation of user IDs. This flaw allows attackers to perform arbitrary PHP file inclusion and probe server directories, potentially exposing site structure and installed plugins. The vulnerability affects the authentication API, users API, and any functionality using $users->find() with user-supplied input. The issue was fixed in version 5.4.1. Join the discussion | CVE Database V5 | 07/16/2026, 21:19:16 UTC Added: 07/16/2026, 21:48:08 UTC |
0 Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing attackers to include arbitrary model methods in their queries. This includes methods with sensitive data such as password() (disclosing the password hash) or root() (disclosing the absolute filesystem path on the server) as well as methods that perform impactful actions such as loginPasswordless() (causing a privilege escalation to another user) or delete() (deleting all queried models in one go if the authenticated user has appropriate permissions). This issue has been fixed in versions 4.9.1 and 5.4.1. Join the discussion | CVE Database V5 | 07/16/2026, 21:13:43 UTC Added: 07/16/2026, 21:48:08 UTC |
0 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4. Join the discussion | CVE Database V5 | 07/09/2026, 18:48:50 UTC Added: 07/09/2026, 19:18:15 UTC |
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users who know or guess page IDs or UUIDs to retrieve page information, including full content and metadata, for arbitrary published pages through the /api/site/find route without authorization to access those pages. This issue is fixed in versions 4.9.4 and 5.4.4. Join the discussion | CVE Database V5 | 07/09/2026, 18:47:02 UTC Added: 07/09/2026, 19:18:15 UTC |
0 Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4. Join the discussion | CVE Database V5 | 07/09/2026, 18:44:56 UTC Added: 07/09/2026, 19:18:15 UTC |
Showing 1 to 10 of 26 results