The Kirby core
89%
Total Score
100
69
80
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-54005 getkirby/cms is vulnerable to Missing Authorization in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3. | 0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3 | High |
CVE-2026-54004 getkirby/cms is vulnerable to Missing Authorization in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3. | 0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3 | Medium |
CVE-2026-54003 getkirby/cms is vulnerable to External Initialization of Trusted Variables or Data Stores in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3. | 0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3 | Critical |
CVE-2026-54002 getkirby/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3. | 0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3 | High |
CVE-2026-50188 getkirby/cms is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.0 - 4.9.3 and 5.0.0-alpha.1 - 5.4.3. | 0.0.0 - 4.9.35.0.0-alpha.1 - 5.4.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
filp/whoops Version 2.18.4 | — | — |
symfony/yaml Version 7.4.14 | — | — |
composer/semver Version 3.4.4 | — | — |
erusev/parsedown Version 1.8.0 | — | — |
phpmailer/phpmailer Version 7.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant