{"id":"CVE-2026-49276","aliases":["GHSA-rhj6-r49h-5932"],"url":"https://o3.security/vulnerability/CVE-2026-49276","summary":"Kirby: Self cross-site scripting (self-XSS) in the writer field","details":"Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link to be included as the target of a link or email link in writer mark components, making the target clickable by the user who entered it and enabling self cross-site scripting in the Panel. This issue is fixed in versions 4.9.4 and 5.4.4.","published":"2026-07-09T18:48:50.543Z","modified":"2026-08-12T03:51:24.007138165Z","cvss":null,"epss":{"score":0.00289,"percentile":0.21514,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getkirby/cms","fixedVersion":"4.9.4"},{"ecosystem":"Packagist","name":"getkirby/cms","fixedVersion":"5.4.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/4.9.4"},{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/5.4.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49276.json"},{"type":"ADVISORY","url":"https://github.com/getkirby/kirby/security/advisories/GHSA-rhj6-r49h-5932"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49276"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.007138165Z"}}