Cross-site scripting in Kirby - #VU150666
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary scripts in the browsers of site visitors and logged-in users.
The vulnerability exists due to improper neutralization of imported HTML in Kirby\'s HTML importer for blocks when importing HTML into blocks or layout fields. A remote user can paste crafted table or non-video iframe HTML into an updatable field to execute arbitrary scripts in the browsers of site visitors and logged-in users.
The Panel does not render imported block content as HTML.