CVE-2026-32870Disclosure(getkirby / kirby)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a second time but allowed to pass through. However, prior to versions 4.9.0 and 5.4.0, it was possible to trick this check into allowing values that only contained a valid `CDATA` block but also contained other structured data outside of the `CDATA` block. This structured data would then also be allowed to pass through, circumventing the value protection. The `Xml::value()` method is used in `Xml::tag()`, `Xml::create()` and in the `Xml` data handler (e.g. `Data::encode($string, 'xml')`). Both the vulnerable methods and the data handler are not used in the Kirby core. However they may be used in site or plugin code, e.g. to create XML strings from input data. If those generated files are passed to another implementation that assigns specific meaning to the XML schema, manipulation of this system's behavior is possible. Kirby sites that don't use XML generation in site or plugin code are not affected. The problem has been patched in Kirby 4.9.0 and Kirby 5.4.0. In all of the mentioned releases, Kirby has added additional checks that only allow unchanged `CDATA` passthrough if the entire string is made up of valid `CDATA` blocks and no structured data. This protects all uses of the method against the described vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-91

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kirby

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
kirby

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-25: 2Mentions · 2026-04-28: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 104-2504-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-252
Disclosure1General1
2026-04-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-32870: CVE-2026-32870: XML Injection via Unsafe CDATA Handling in Kirby CMS Toolkit Kirby CMS versions prior to 4.9.0 and 5.0.0 through 5.3.x are vulnerable to XML Injection (CWE-91). An insecure heuristic within the Toolkit's XML handling me... https://cvereports.com/reports/CVE-2026-32870

    Post summary

    The text announces the discovery of an XML Injection vulnerability (CWE‑91) in Kirby CMS versions prior to 4.9.0 and 5.0.0‑5.3.x, detailing the affected payload handling but providing no PoC, exploit, or mitigation.

    0000036
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32870 Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `` blocks. If the input value is already valid … https://www.cve.org/CVERecord?id=CVE-2026-32870 ----- Traducción: CVE-2026-32870 Kirby es un sist… http://infoflow.cloud`

    Post summary

    The post cites CVE-2026-32870 affecting Kirby CMS, noting the special handling of `` blocks in the Xml::value() method and links to the CVE record; no PoC, exploit, patch, or active exploitation is mentioned.

    0000023
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32870 Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `&lt;![CDATA[ ]]&gt;` blocks. If the input value is already valid … https://www.cve.org/CVERecord?id=CVE-2026-32870

    Post summary

    The text only references a new CVE for Kirby's XML handling but provides no further technical detail, proof of concept, or evidence of exploitation or mitigation.

    00000126
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetkirbykirby---

Explore more