Xibo CMS是Xibo Digital Signage开源的一个内容管理系统。 Xibo CMS 1.7版本至4.4.0版本存在SQL注入漏洞,该漏洞源于API路由中数据集过滤参数存在SQL注入,可能导致授权用户获取和修改数据库任意数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xibosignage | xibo-cms | >= 1.7, < 4.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-31953 | 6.4 MEDIUM | Xibo CMS has Stored XSS via Notification Body with Zero-Click Execution on Login |
| CVE-2026-31955 | 4.9 MEDIUM | Xibo CMS has Authenticated Server-Side Request Forgery (SSRF) in Remote DataSet Functional |
| CVE-2026-31956 | 4.3 MEDIUM | Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level au |
No comments yet