Xibosignage develops a focused digital signage and display-management platform whose vulnerability profile centers on web-application and access-control weaknesses endemic to remotely administered systems. The recurring exposure spans SQL injection, cross-site scripting, path traversal, authorization bypass, and cross-site request forgery—a cluster of input-validation and privilege-handling flaws characteristic of web-facing management interfaces—and the vendor's disclosures have an elevated tendency toward public exploit availability. Defenders managing Xibosignage deployments should prioritize network segmentation of the management layer and treat authentication and input-validation patches as operationally urgent; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xibosignage over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33177HIGH Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout impo | May 30, 2023 | 8.8 | 40 | NO | YES |
CVE-2013-5979MEDIUM Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p param | Oct 2, 2013 | 5.0 | 38 | NO | YES |
CVE-2026-31952HIGH Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerabi | Apr 24, 2026 | 8.1 | 27 | NO | NO |
CVE-2013-4889MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the authentication of administrators for requ | Jan 29, 2014 | 6.8 | 26 | NO | YES |
CVE-2024-41802HIGH Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authent | Jul 30, 2024 | 8.1 | 25 | NO | NO |
CVE-2025-62369HIGH Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Develo | Nov 4, 2025 | 7.2 | 24 | NO | NO |
CVE-2023-33180MEDIUM Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside | May 30, 2023 | 6.5 | 21 | NO | NO |
CVE-2013-4888MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the l | Jan 29, 2014 | 4.3 | 21 | NO | YES |
CVE-2026-31953MEDIUM Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versi | Apr 24, 2026 | 5.4 | 20 | NO | NO |
CVE-2023-33179MEDIUM Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used thro | May 30, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xibosignage.
Media articles that mention a CVE ID that affects a product developed by Xibosignage — matched by CVE ID, not by vendor name.