Stored Cross-Site Scripting Vulnerability in Xibo Digital Signage Platform
CVE-2026-31953
6.4MEDIUM
What is CVE-2026-31953?
The Xibo digital signage platform has a stored Cross-Site Scripting vulnerability that affects versions prior to 4.4.1. An authenticated user with notification creation permissions can inject malicious JavaScript into notification bodies. If set to interrupt, this code executes automatically in the browser of any targeted user upon login without any required interaction. This flaw necessitates the need for users to gain specific privileges, including access to past notifications and the ability to create new ones. To safeguard installations, users are advised to upgrade to version 4.4.1, which addresses the vulnerability; those unable to update should restrict notification creation permissions to trusted users only.
Affected Version(s)
xibo-cms < 4.4.1
