๐Ÿ” CVE Alert

CVE-2026-42141

HIGH 7.7

Xibo: Authenticated Server-Side Request Forgery (SSRF) in Library Upload via URL functionality

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal infrastructure, access local cloud metadata endpoints (e.g., AWS IMDS), interact with internal services that lack authentication, or exfiltrate data. This vulnerability is fixed in 4.4.1.

CWE CWE-918
Vendor xibosignage
Product xibo-cms
Published May 12, 2026
Last Updated May 13, 2026
Stay Ahead of the Next One

Get instant alerts for xibosignage xibo-cms

Be the first to know when new high vulnerabilities affecting xibosignage xibo-cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

xibosignage / xibo-cms
< 4.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-fwq8-c4gw-pxmh