Record summary

CVE-2026-49276 has a selected CVSS score of 7.4 (high).

Description

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 10, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 4.9.4affected
>= 5.0.0, < 5.4.4affected
GitHub AdvisoryBefore 4.9.4 · Fixed in 4.9.4affected
5.0.0-alpha.1 to < 5.4.4 · Fixed in 5.4.4affected

References

4