Product
xibosignage xibo
19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-31956
CVE-2026-31955
CVE-2026-31953
CVE-2026-31952
CVE-2025-62369
CVE-2024-43413
CVE-2024-43412
CVE-2024-41804
CVE-2024-41803
CVE-2024-41802
CVE-2023-33181
CVE-2023-33180
CVE-2023-33179
CVE-2023-33178
CVE-2023-33177
CVE-2013-4889
CVE-2013-4888
CVE-2013-4887
CVE-2013-5979
< 4.4.1
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to
< 4.4.1
Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authe
< 4.4.1
Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored
>= 1.7.0 and < 4.4.1
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions
>= 4.1.0 and < 4.3.1
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Rem
< 4.1.0
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site s
< 4.1.0
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site s
>= 2.1.0 and < 3.3.12
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsib
>= 2.1.0 and < 3.3.12
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsi
>= 2.1.0 and < 3.3.12
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsi
>= 3.0.0 and < 3.3.5
Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stac
>= 3.2.0 and < 3.3.5
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to ve
>= 3.2.0 and < 3.3.5
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to ve
>= 1.4.0 and < 2.3.17
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the
/dataset/data/{id} API route ins>= 1.8.0 and < 2.3.17
Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip f
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hi
all versions
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary we
all versions
SQL injection vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to execute arbitrary SQL commands v
all versions
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read