An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization such that the reporter's mentioned "injecting malicious scripts" would not occur.
Cite this page
CVE-2024-26482. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-26482
Use CWE-80, Getkirby vendor hub and Kirby product page to widen CVE-2024-26482 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-41964, CVE-2026-34587 and CVE-2026-41325 for nearby disclosures in the same product family.