ZeroHour

CVE-2026-29905

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p38
Published
()
Modified
Description

Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file for metadata or thumbnail generation, it triggers a fatal TypeError.

Vendors
getkirby
Products
kirby
Weakness
CWE-20, CWE-252
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.