{"id":"CVE-2024-26484","details":"A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this issue did not affect any version of Kirby CMS. The only effect was on the trykirby.com demo site, which is not customer-controlled.","modified":"2026-04-10T05:11:51.244818Z","published":"2024-02-22T05:15:10.037Z","references":[{"type":"FIX","url":"https://github.com/getkirby/demokit/commit/d4877a6715cbf6517cb04ff57798851ffbd0cd7e"},{"type":"EVIDENCE","url":"https://shrouded-trowel-50c.notion.site/Kirby-CMS-4-1-0-Stored-Cross-Site-Scripting-153b4eb557a2488188ad8167734ca226?pvs=4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getkirby/demokit","events":[{"introduced":"0"},{"fixed":"d4877a6715cbf6517cb04ff57798851ffbd0cd7e"}]},{"type":"GIT","repo":"https://github.com/getkirby/kirby","events":[{"introduced":"0"},{"last_affected":"2965c3124e3b141072a2d46c798a327dda710060"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"4.1.0-NA"}]}}],"versions":["3.0.0","3.0.1","3.0.2","3.0.2-rc.1","3.0.3","3.0.3-rc.1","3.0.3-rc.2","3.0.3-rc.3","3.1.0","3.1.0-rc.1","3.1.1","3.1.2","3.1.2-rc.1","3.1.3","3.1.3-rc.1","3.1.4","3.1.4-rc.1","3.2.0","3.2.0-rc.1","3.2.0-rc.2","3.2.0-rc.3","3.2.0-rc.4","3.2.1","3.2.1-rc.1","3.2.2","3.2.3-rc.1","3.2.5","3.2.5-rc.1","3.2.5-rc.2","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.4.0","3.4.1","3.4.2","3.4.3","3.5.0","3.5.0-rc.1","3.5.0-rc.2","3.5.0-rc.3","3.5.0-rc.4","3.5.0-rc.5","3.5.0-rc.6","3.5.0-rc.7","3.5.1","3.5.1-rc.1","3.5.2","3.5.3","3.5.3.1","3.5.4","3.5.5","3.5.6","3.5.7","3.5.7.1","3.6.0","3.6.1.1","3.6.2","3.6.2-rc.1","3.6.2-rc.2","3.6.2-rc.3","3.6.3","3.6.3.1","3.6.4","3.6.5","3.6.6","3.7.0","3.7.0.1","3.7.0.2","3.7.1","3.7.2","3.7.2.1","3.7.3","3.7.4","3.7.4-rc.1","3.7.5","3.8.0","3.8.1","3.8.1.1","3.8.2","3.8.3","3.8.4","3.9.0","3.9.1","3.9.2","3.9.3","3.9.4","3.9.5","3.9.6","3.9.6-rc.1","3.9.6.1","3.9.7","3.9.8","4.0.0","4.0.1","4.0.2","4.0.3","4.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26484.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}