CVE-2025-41088

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add a text element in the 'Global Elements' section, and finally modify the 'Text' field in the section with the malicious payload.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Oct 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-10 10:15

Updated : 2025-10-14 19:37


NVD link : CVE-2025-41088

Mitre link : CVE-2025-41088

CVE.ORG link : CVE-2025-41088


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')