Kirby has released security fixes for multiple high-severity vulnerabilities affecting its CMS, including a pre-authentication path traversal and PHP file inclusion bug tracked as CVE-2026-44177. The flaw affects 5.3.0 through 5.4.0 and stems from improper validation of user IDs after lazy loading was introduced for the Users collection, exposing the authentication API, users API, and other code paths using user lookups. Advisories say successful exploitation could allow arbitrary inclusion of PHP files named index.php and enable directory probing for server and site fingerprinting. Kirby also patched CVE-2026-44174, an arbitrary method call issue in REST API search and collection query endpoints that could lead to sensitive information disclosure, privilege escalation, or destructive actions such as deleting queried models when permissions allowed.
The update also closes multiple frontend cross-site scripting vulnerabilities. CVE-2026-44175 allowed persistent XSS because list field content was not sanitized on save, letting malicious HTML be stored through Kirby's API and later executed in visitors' and logged-in users' browsers. CVE-2026-45368 affected KirbyTags, image blocks, and imported HTML because malicious URL schemes such as javascript: and similar variants could bypass filtering and trigger script execution. The issues affect versions earlier than 4.9.1 and 5.0.0 through 5.4.0, and were fixed in 4.9.1 and 5.4.1; the release also included additional hardening, fixes for authorization and information disclosure issues, and an updated symfony/yaml dependency.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
GitHub Security Advisories received CVE-2026-44174 on 2026-07-16. The vulnerability affects Kirby versions earlier than 4.9.1 and 5.0.0 through before 5.4.1, allowing arbitrary model method invocation via REST API search and collection query endpoints.
On 2026-05-19, Kirby published release 5.4.1 to fix multiple security issues, including the pre-authentication path traversal/PHP file inclusion flaw, arbitrary method calls via REST API endpoints, and several frontend XSS vectors. The release also included additional hardening changes and a patched symfony/yaml dependency.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.