CVE-2026-42174
MEDIUM SEVERITYVulnerability Description
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-862
Source
GitHub
Vendor
composer
Product
getkirby/cms
Discussion (0)
Add Comment
No comments yet. Be the first!