CVE-2026-42051
MEDIUM4.3CVSS v3
—CVSS v2
0.03%
EPSS (exploit probability)
CWE-862CWE
Description
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patched in versions 4.9.0 and 5.4.0.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.