Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 patch commits.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 08 Dec 2025 22:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*

Thu, 06 Nov 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Nov 2025 20:00:00 +0900

Type Values Removed Values Added
First Time appeared Xibosignage
Xibosignage xibo
Vendors & Products Xibosignage
Xibosignage xibo

Wed, 05 Nov 2025 07:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Nov 2025 06:30:00 +0900

Type Values Removed Values Added
Description Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 patch commits.
Title Xibo CMS: Remote Code Execution through module templates
Weaknesses CWE-1336
CWE-94
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-05T14:29:33.887Z

Reserved: 2025-10-10T14:22:48.204Z

Link: CVE-2025-62369

cve-icon Vulnrichment

Updated: 2025-11-04T21:37:15.229Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-04T22:16:38.160

Modified: 2025-12-08T13:30:12.790

Link: CVE-2025-62369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-05T19:47:07Z

Weaknesses