CVE-2026-42174EPSS p23.4%
CVE-2026-42174CVE-2026-42174
getkirby / kirby
Description
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.33% probability of exploitation · percentile 23.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-24 |