github.com
https://github.com/getkirby/kirby CVE-2026-49276
HIGH
Kirby: Self cross-site scripting (self-XSS) in the writer field
Record summary
CVE-2026-49276 has a selected CVSS score of 7.4 (high).
Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 10, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 4.9.4 | affected | |
| >= 5.0.0, < 5.4.4 | affected | ||
getkirby/cmsBrowse Packagist / getkirby/cms | GitHub Advisory | Before 4.9.4 · Fixed in 4.9.4 | affected |
| 5.0.0-alpha.1 to < 5.4.4 · Fixed in 5.4.4 | affected |
References
4github.com
https://github.com/getkirby/kirby/releases/tag/4.9.4 github.com
https://github.com/getkirby/kirby/releases/tag/5.4.4 github.comConfirmation
https://github.com/getkirby/kirby/security/advisories/GHSA-rhj6-r49h-5932