Improper Neutralization of Alternate XSS Syntax in Kirby - #VU150664
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script.
The vulnerability exists due to improper neutralization of alternate cross-site scripting syntax in Dom::sanitize() when sanitizing SVG or XML content for inline embedding. A remote user can submit crafted SVG or XML content for inline rendering to execute arbitrary script.
The rendered page must be viewed by another user.