Xibo是Dan Garner个人开发者的一款数字标牌内容管理工具。 Xibo 4.4.1之前版本存在跨站脚本漏洞,该漏洞源于通知正文存储型跨站脚本,可能导致授权用户在目标用户登录时自动执行恶意JavaScript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xibosignage | xibo-cms | < 4.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-31952 | 7.6 HIGH | Xibo CMS API has SQL Injection via DataSet Filter Parameter |
| CVE-2026-31955 | 4.9 MEDIUM | Xibo CMS has Authenticated Server-Side Request Forgery (SSRF) in Remote DataSet Functional |
| CVE-2026-31956 | 4.3 MEDIUM | Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level au |
No comments yet