PT-2026-34812 · Xibo · Xibo

Swarnimbandekar

·

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-31953

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions prior to 4.4.1
Description A stored Cross-Site Scripting (XSS) issue allows an authenticated user with notification creation permissions to inject arbitrary JavaScript into the notification body. When a notification is configured as an "interrupt," the payload executes automatically in the browser of targeted users upon login without requiring interaction. This requires the attacker to have privileges to access the Notification Centre and the ability to use the "Add Notification" button, permissions typically not granted to non-administrators.
Recommendations Upgrade to version 4.4.1. Revoke notification creation and Notification Centre access privileges from untrusted users as a temporary workaround.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31953

Affected Products

Xibo