getkirby/cms Security Advisories for 4.9.4 (3)
-
[MEDIUM] Kirby: Access to image files outside of the site root via path traversal in the media handling
PKSA-cmzk-n5t6-2v3k CVE-2026-75592 GHSA-6j4c-mgqr-qv76
Affected version: >=5.0.0,<5.5.2|<4.9.5
Reported by:
GitHub -
[MEDIUM] Kirby: System path exposure from error messages in the REST API
PKSA-wq8z-fxnn-1fxz CVE-2026-69127 GHSA-rf2p-vh74-7vvh
Affected version: >=5.0.0,<5.5.2|<=4.9.4
Reported by:
GitHub -
[HIGH] Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
PKSA-n74d-ghht-18nt CVE-2026-75594 GHSA-9vx2-j98c-p72w
Affected version: >=5.0.0,<5.5.2|<=4.9.4
Reported by:
GitHub