VYPR

Xibo

by Xibosignage

Source repositories

CVEs (25)

  • CVE-2024-43412MedSep 3, 2024
    risk 0.00cvss 4.6epss 0.00

    Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Users can upload…

  • CVE-2024-41804MedJul 30, 2024
    risk 0.00cvss 6.5epss 0.00

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by…

  • CVE-2024-41803MedJul 30, 2024
    risk 0.00cvss 4.9epss 0.00

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted…

  • CVE-2024-41802HigJul 30, 2024
    risk 0.00cvss 8.1epss 0.00

    Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially…

  • CVE-2013-4887Jan 29, 2014
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to execute arbitrary SQL commands via the displayid parameter.

Page 2 of 2