Cross-site scripting in Kirby - #VU150658
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the browsers of Panel users.
The vulnerability exists due to cross-site scripting in Kirby language variables when rendering overwritten translation strings as HTML. A remote user can create or update a language with a malicious variable that overwrites a built-in translation string to execute arbitrary script in the browsers of Panel users.
Exploitation affects multi-language sites and requires a victim to open the Panel in the affected language.