Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-39cp-6679-8xv2 | Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getkirby
Getkirby kirby |
|
| Vendors & Products |
Getkirby
Getkirby kirby |
Sat, 09 May 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0. | |
| Title | Kirby: User avatar creation, replacement and deletion are not gated by user update permissions | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-09T03:39:06.016Z
Reserved: 2026-04-25T01:53:21.582Z
Link: CVE-2026-42174
No data.
Status : Received
Published: 2026-05-09T04:16:23.600
Modified: 2026-05-09T04:16:23.600
Link: CVE-2026-42174
No data.
OpenCVE Enrichment
Updated: 2026-05-09T06:00:12Z
Weaknesses
Github GHSA