Cross-Site Scripting Vulnerability in Kirby CMS Versions Prior to 4.9.1 and 5.4.1
CVE-2026-44175
What is CVE-2026-44175?
Kirby, a popular open-source content management system, had a vulnerability in its list field feature prior to versions 4.9.1 and 5.4.1. This security issue arose from inadequate sanitization of HTML content stored within the list field, which could be exploited by attackers. Unsanitized HTML allowed malicious scripts to be entered and executed in the web browser of users visiting affected sites. The vulnerability was particularly critical as the server did not adequately sanitize the content on save, and the enforcement was only seen client-side in the management Panel. Upon this exploitation, persistent XSS could occur, jeopardizing the security of both site visitors and authenticated users. Users are strongly advised to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
kirby < 4.9.1 < 4.9.1
kirby >= 5.0.0, < 5.4.1 < 5.0.0, 5.4.1
