Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
| Software | From | Fixed in |
|---|---|---|
getkirby / kirby
|
2.5.12 | 2.5.12.x |