CVE-2026-45368 is a stored cross-site scripting vulnerability in Kirby CMS affecting versions prior to 4.9.1 and versions 5.0.0 through 5.4.0. The flaw is caused by insufficient filtering of attacker-controlled URL values in the URL handling used by KirbyTags and image block rendering. Four first-party rendering paths are affected: the (link: …) KirbyTag, the link parameter of the (image: …) KirbyTag when it does not resolve to a known file or self, the link field of the built-in image block, and the HTML importer for the blocks field. These components generate anchor elements from editor-supplied values and failed to reject dangerous URI schemes that can resolve to script execution. Existing handling blocked some malformed javascript: inputs by converting them to relative paths, but this protection could be bypassed with crafted values such as javascript://... containing a newline sequence. The same validation gap also affected other dangerous schemes including vbscript:, data:, livescript:, mocha:, and jar:. When malicious content is stored and later rendered in the site frontend, clicking the resulting link can execute attacker-supplied script in the victim's browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
(link: …) KirbyTag, the link parameter of the (image: …) KirbyTag, the built-in image block with links, and the blocks HTML importer. Restrict update permissions for textarea and blocks fields, review any workflow that permits direct writes to content files, and avoid passing untrusted input into helper functions that generate links. Exposure is reduced if affected renderers are unused or if all content authors are fully trusted.Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.