Back to Database
Status published
Unknown
CVE-2018-14520
An issue was discovered in Kirby 2.5.12. The application allows...
Vulnerability Description
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-14520
Credits & Attribution
No credits recorded in the NVD database.
References
More from getkirby
View All →CVE-2025-65012
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
5.1
CVE-2025-31493
Path traversal of collection names during file system lookup
Medium
6.3
CVE-2025-30207
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
2.3
CVE-2025-30159
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
Medium
6.3
CVE-2024-41964
Insufficient permission checks in the language settings in Kirby CMS
High
8.1
Affected Vendor
getkirby
View all reports →Affected Software
kirby
Vulnerable Versions:
2.5.12
Timeline
Official Publish:
August 24th, 2022
Last Modified:
June 17th, 2025
Added to House:
July 20th, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.