Product
high
threat
Kirby CMS Arbitrary Method Call Vulnerability via REST API
2 rules 1 TTPKirby CMS is vulnerable to arbitrary method call via REST API search and collection query endpoints, allowing attackers to execute sensitive methods like password disclosure or privilege escalation, patched in versions 4.9.1 and 5.4.1.
cms +1
arbitrary-code-execution
privilege-escalation
web-application
2r
1t
high
threat
Kirby CMS Vulnerable to Cross-Site Scripting (XSS) via List Field Content (CVE-2026-44175)
2 rules 1 TTPKirby CMS is vulnerable to cross-site scripting (XSS) via the list field or list block, allowing an authenticated Panel user with update permission to inject malicious HTML code into the content file, which is then executed in the browsers of site visitors and logged-in users; the vulnerability is tracked as CVE-2026-44175 and has been patched in versions 4.9.1 and 5.4.1.
cms +1
xss
CVE-2026-44175
kirby-cms
web-application
2r
1t