PT-2026-43211 · Xibo Cms · Xibo Cms

CVE-2026-42558

·

Published

2026-05-26

·

Updated

2026-06-11

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Xibo CMS versions prior to 4.4.2
Description A vulnerability chain involving Stored Cross-Site Scripting (XSS) and Iframe Sandbox escape exists in the Xibo CMS. Users with DataSet permissions can utilize the Data Connector functionality to craft messages that escape the sandbox and facilitate XSS. This exploitation requires an authorized user to possess specific privileges, such as the ability to use the "Add DataSet" button to create DataSets independently of Layouts, which are typically not granted to non-administrators by default.
Recommendations Upgrade to version 4.4.2. Revoke privileges related to the "Add DataSet" button from untrusted users as a temporary mitigation.

Exploit

Fix

XSS

Origin Validation Error

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42558
GHSA-6389-J56C-9FWW

Affected Products

Xibo Cms