Multiple security vulnerabilities have been identified in getkirby/cms, affecting versions not explicitly stated in this article. The overall risk and impact are significant, as attackers can exploit these vulnerabilities to gain unauthorized access to sensitive data.
CVE-2026-75594 (CVSS 7.5 — High): An attacker can access image files and limited access to JSON files outside of the site root via path traversal in the media handling of Kirby.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in getkirby/cms, affecting versions not explicitly stated in this article. The overall risk and impact are significant, as attackers can exploit these vulnerabilities to gain unauthorized access to sensitive data.
CVE-2026-75594 (CVSS 7.5 — High): An attacker can access image files and limited access to JSON files outside of the site root via path traversal in the media handling of Kirby.[emaillocker id="1283"]
CVE-2026-71415: File upload permissions are not checked during processing of chunk data, allowing an attacker to potentially exploit this vulnerability.
These vulnerabilities collectively present a significant risk to administrators who have not applied patches.
We recommend you to update getkirby/cms to version 5.5.2
The following reports contain further technical details:
[/emaillocker]