CVE-2026-31952Disclosure(xibosignage / xibo)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerability in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the API filter parameter. Exploitation of the vulnerability is possible on behalf of an authorized user who has either of the `Access to DataSet Feature` privilege or the `Access to the Layout Feature` privilege. Users should upgrade to version 4.4.1 which fixes this issue. Customers who host their CMS with Xibo Signage have been patched if they are using 4.4, 4.3, 3.3, 2.3 or 1.8. Upgrading to a fixed version is necessary to remediate. Patches are available for earlier versions of Xibo CMS that are out of support, namely 3.3, 2.3, and 1.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xibo

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
xibo

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-25: 2Technical Details · 2026-04-25: 204-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-31952 Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injec… https://www.cve.org/CVERecord?id=CVE-2026-31952

    Post summary

    CVE‑2026‑31952 is an SQL injection flaw present in Xibo versions 1.7–4.4.0, as disclosed in the CVE record, with no PoC, exploit, or patch details provided.

    00010123
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31952 Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injec… https://www.cve.org/CVERecord?id=CVE-2026-31952 ----- Traducción: CVE-2026-31952 Xib… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑31952, noting an SQL injection flaw in Xibo digital signage software and links to the official CVE record for details.

    0000036
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxibosignagexibo---

Explore more