{"id":"CVE-2026-54002","aliases":["GHSA-wr9h-4r83-f4v6"],"url":"https://o3.security/vulnerability/CVE-2026-54002","summary":"Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`","details":"Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call Dom::sanitize(), Sane::sanitize(), Sane::Html::sanitize(), Sane::Svg::sanitize(), Sane::Xml::sanitize(), Sane::sanitizeFile(), or file sanitizeContents() with untrusted input allow malicious markup injected as children of an unknown HTML or XML tag to pass through Dom::sanitize() without being correctly sanitized, causing stored cross-site scripting. This issue is fixed in versions 4.9.4 and 5.4.4.","published":"2026-07-09T18:34:29.041Z","modified":"2026-08-12T03:51:25.918028575Z","cvss":null,"epss":{"score":0.00409,"percentile":0.34315,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getkirby/cms","fixedVersion":"4.9.4"},{"ecosystem":"Packagist","name":"getkirby/cms","fixedVersion":"5.4.4"}],"fix":{"url":"https://github.com/getkirby/kirby/commit/0f0437b5128c910103cbc78fc34d94b2a3faef4c","label":"getkirby/kirby@0f0437b"},"references":[{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/4.9.4"},{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/5.4.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54002.json"},{"type":"ADVISORY","url":"https://github.com/getkirby/kirby/security/advisories/GHSA-wr9h-4r83-f4v6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54002"},{"type":"FIX","url":"https://github.com/getkirby/kirby/commit/0f0437b5128c910103cbc78fc34d94b2a3faef4c"},{"type":"FIX","url":"https://github.com/getkirby/kirby/commit/7ad76cf9c7387462828e6ebfc8404e31b37829e9"},{"type":"FIX","url":"https://github.com/getkirby/kirby/commit/9ec1873864441dbc06479ef7823da348ec7f2700"},{"type":"FIX","url":"https://github.com/getkirby/kirby/commit/bb2562e16c754493a403b8df84c9883108871e4c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.918028575Z"}}