CVE-2026-45368
📛 CVE Title
(no title)
Description
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 6.1 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N- Effective score
- 6.1 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45368
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-07-16 22:17:02 UTC
- NVD last modified
- 2026-07-18 05:16:53 UTC
- EPSS score
- 0.0033 (probability of exploitation in next 30 days)
- EPSS percentile
- 25.99% vs all CVEs — higher = more likely to be exploited, as of 2026-08-01
NVD-assigned CWE(s):
CWE-79
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-08-01 16:28 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-45058 - Assigner
- GitHub_M
- Published
- Jul 16, 2026, 9:49:46 PM
- Updated
- Jul 18, 2026, 3:18:56 AM
- EUVD base score (CVSS 4.0)
-
8.4 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.3300
- Vendors
- getkirby
- Products
-
kirby (5.0.0, < 5.4.1)kirby (< 4.9.1)
- Aliases
-
GHSA-qvjf-922g-pj44
ENISA description: Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components did not filter out malicious URL values that resolve to script execution. The vulnerability affects four first-party Kirby renderers that produce `<a href="…">` output from editor-supplied field values: the (`link: …)` KirbyTag, the `link`: parameter of the `(image: …)` KirbyTag when it does not resolve to a known file or `self`, the `link` field of the built-in image block, and the HTML importer for the `blocks` field (which accepted the same malicious input as the image block `link` field). While simple `avascript:` URLs were already deactivated by treating them as a relative path and prepending a single slash to the URL, the use of URLs of the format `javascript://x%0A…` bypasses this protection. The `vbscript:`, `data:`, `livescript:`, `mocha:` and `jar:` schemes are affected by the same underlying gap. This issue has been fixed in versions 4.9.1 and 5.4.1.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (2)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2026-45368 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45368 tenable:www.cve.org
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/getkirby/kirby/releases/tag/5.4.1 security-advisories@github.com
- https://github.com/getkirby/kirby/security/advisories/GHSA-qvjf-922g-pj44 security-advisories@github.com
Remediations (10)
-
web:blogs.oracle.com
As a follow-up to our recent post, Accelerating Vulnerability Detection and Response, Oracle is announcing the start date and cadence for monthly Critical Security Patch Updates (CSPUs). Beginning May 28, 2026 , Oracle will deliver a Critical Security Patch Update (CSPU) each month.
2026-06-19 02:54 UTC -
web:cyberscoop.com
Threats Microsoft addresses 137 vulnerabilities in May's Patch Tuesday, including 13 rated critical The high volume of vulnerabilities reflects a growing trend researchers have been anticipating as artificial intelligence models are deployed to find previously uncovered defects in code.
2026-06-19 02:54 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-19 02:54 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-19 02:54 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's May 2026 Patch Tuesday, with security updates for 120 flaws and no zero-days disclosed this month.
2026-06-19 02:54 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 130 vulnerabilities, including 30 critical, in its May 2026 Patch Tuesday rollout.
2026-06-19 02:54 UTC -
web:www.helpnetsecurity.com
Microsoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE -numbered vulnerabilities, none of which are actively exploited.
2026-06-19 02:54 UTC -
web:www.lansweeper.com
Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday May 2026 summary.
2026-06-19 02:54 UTC -
web:www.oracle.com
This Critical Security Patch Update contains 35 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at May 2026 Critical Security Patch Update: Executive Summary and Analysis.
2026-06-19 02:54 UTC -
web:www.securityweek.com
Vulnerabilities Oracle's Second Monthly Security Updates Deliver 245 Patches Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products.
2026-06-19 02:54 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.