Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xibosignage
Xibosignage xibo |
|
| CPEs | cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xibosignage
Xibosignage xibo |
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the vulnerability is possible on behalf of an authorized user who has any of the following privileges: Page which shows all Layouts that have been created for the purposes of Layout Management; page which shows all Campaigns that have been created for the purposes of Campaign Management; and page which shows all Reports that have been Saved. Users should upgrade to version 4.4.1 which fixes this issue. Upgrading to a fixed version is necessary to remediate. | |
| Title | Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level authorization | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-24T13:08:17.026Z
Reserved: 2026-03-10T15:40:10.479Z
Link: CVE-2026-31956
Updated: 2026-04-24T13:08:13.308Z
Status : Analyzed
Published: 2026-04-24T01:16:11.773
Modified: 2026-04-27T14:44:42.927
Link: CVE-2026-31956
No data.
OpenCVE Enrichment
Updated: 2026-04-28T08:45:26Z