{"id":"CVE-2017-16807","details":"A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.","aliases":["GHSA-275c-v3rc-xghx"],"modified":"2026-08-19T14:51:43.587224Z","published":"2017-11-13T21:29:00.330Z","references":[{"type":"WEB","url":"https://getkirby.com/changelog/kirby-2-5-7"},{"type":"EVIDENCE","url":"https://packetstormsecurity.com/files/144965/KirbyCMS-Cross-Site-Scripting.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/43140/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getkirby-v2/panel","events":[{"introduced":"0"},{"fixed":"7b8b2efa47db5a92a9319e7d9979065e8d2e5e54"},{"introduced":"7f6e22b172bd84ecaac17cbf02853d627346a8e9"},{"fixed":"df4e13ae7a6a0d04cd564abc455c55c07f1ed096"},{"introduced":"d8ed5ba22df03849e9770250698f48069b069dae"},{"fixed":"9c54ef6cfe68bfa9e1c618cbf42eeaf222f1d833"}],"database_specific":{"cpe":"cpe:2.3:a:getkirby:panel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.3"},{"introduced":"2.4.0"},{"fixed":"2.4.2"},{"introduced":"2.5.0"},{"fixed":"2.5.7"}],"source":"CPE_RANGE"}}],"versions":["2.5.7-RC-1","2.3.2","2.4.1","2.5.6","2.5.6-RC-1","2.5.5","2.5.5-RC-1","2.5.4","2.5.3","2.5.2","2.5.1","2.5.0","2.4.0","2.3.1","2.3.0","2.2.3","2.2.0","2.1.1","2.1.0","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-16807.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}