Stored Cross-Site Scripting Vulnerability in Xibo Digital Signage Platform
CVE-2026-31953

6.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 April 2026

What is CVE-2026-31953?

The Xibo digital signage platform has a stored Cross-Site Scripting vulnerability that affects versions prior to 4.4.1. An authenticated user with notification creation permissions can inject malicious JavaScript into notification bodies. If set to interrupt, this code executes automatically in the browser of any targeted user upon login without any required interaction. This flaw necessitates the need for users to gain specific privileges, including access to past notifications and the ability to create new ones. To safeguard installations, users are advised to upgrade to version 4.4.1, which addresses the vulnerability; those unable to update should restrict notification creation permissions to trusted users only.

Affected Version(s)

xibo-cms < 4.4.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.