Back to Database
Status published
Medium
CVE-2018-16630
Kirby v2.5.12 allows XSS by using the "site files" Add...
Vulnerability Description
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16630
Credits & Attribution
No credits recorded in the NVD database.
More from getkirby
View All →CVE-2025-65012
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Medium
5.1
CVE-2025-31493
Path traversal of collection names during file system lookup
Medium
6.3
CVE-2025-30207
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
2.3
CVE-2025-30159
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
Medium
6.3
CVE-2024-41964
Insufficient permission checks in the language settings in Kirby CMS
High
8.1
Affected Vendor
getkirby
View all reports →Affected Software
kirby
Vulnerable Versions:
2.5.12
Timeline
Official Publish:
December 28th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.