CVE Database
/

CVE-2026-42174

Back to search

CVE-2026-42174

Published: May 9, 2026

Modified: May 11, 2026

PUBLISHED

Description

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.

VendorProductVersions

getkirby

kirby

affected
< 4.9.0
affected
>= 5.0.0, < 5.4.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now