Xibosignage
Xibosignage Xibo: vulnerabilidades y CVE
Xibosignage Xibo tiene 25 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-52730 | Media (4.3) | 0.29% | — | 31 ago 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super… |
| CVE-2026-42558 | Alta (7.6) | 0.15% | — | 10 jun 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the… |
| CVE-2026-42141 | Alta (7.7) | 0.42% | — | 12 may 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS… |
| CVE-2026-31956 | Media (4.3) | 0.30% | — | 24 abr 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview… |
| CVE-2026-31955 | Media (4.9) | 0.48% | — | 24 abr 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 4.4.1… |
| CVE-2026-31953 | Media (5.4) | 0.24% | — | 24 abr 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.4.1 allows an… |
| CVE-2026-31952 | Alta (8.1) | 0.40% | — | 24 abr 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerability in the API routes inside the CMS… |
| CVE-2025-62369 | Alta (7.2) | 0.90% | — | 4 nov 2025 | Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating… |
| CVE-2024-43413 | Media (4.8) | 0.28% | — | 3 sept 2024 | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the… |
| CVE-2024-43412 | Media (5.4) | 0.28% | — | 3 sept 2024 | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary… |
| CVE-2024-41944 | Media (6.5) | 0.44% | — | 30 jul 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated user to to obtain and modify… |
| CVE-2024-41804 | Media (6.5) | 0.43% | — | 30 jul 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to… |
| CVE-2024-41803 | Media (4.9) | 0.44% | — | 30 jul 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data… |
| CVE-2024-41802 | Alta (8.1) | 0.46% | — | 30 jul 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify… |
| CVE-2024-29023 | Alta (7.2) | 0.80% | — | 12 abr 2024 | Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. Session tokens are exposed in the return of session search API call on the sessions page.… |
| CVE-2024-29022 | Alta (8.8) | 0.70% | — | 12 abr 2024 | Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers are not correctly sanitised when stored in the session… |
| CVE-2023-33181 | Media (5.3) | 0.54% | — | 30 may 2023 | Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information… |
| CVE-2023-33180 | Media (6.5) | 0.62% | — | 30 may 2023 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside the CMS. This allows an authenticated… |
| CVE-2023-33179 | Media (6.5) | 0.62% | — | 30 may 2023 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used throughout the CMS. This allows an… |
| CVE-2023-33178 | Media (6.5) | 0.63% | — | 30 may 2023 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API route inside the CMS starting in version 1.4.0 and prior to versions 2.3.17 and 3.3.5. This allows… |
| CVE-2023-33177 | Alta (8.8) | 7.0% | — | 30 may 2023 | Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user… |
| CVE-2013-4889 | Media (6.8) | 0.85% | — | 29 ene 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new administrator… |
| CVE-2013-4888 | Media (4.3) | 1.4% | — | 29 ene 2014 | Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page. |
| CVE-2013-4887 | Alta (7.5) | 1.2% | — | 29 ene 2014 | SQL injection vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to execute arbitrary SQL commands via the displayid parameter. |
| CVE-2013-5979 | Media (5) | 18% | — | 2 oct 2013 | Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.