6.9

CVSS4.0

CVE-2026-32870 - Kirby has XML injection in its XML creator toolkit

Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a second time but allowed to pass through. However, prior to versions 4.9.0 and 5.4.0, it was possible to …

📅 Published: April 24, 2026, 12:19 a.m. 🔄 Last Modified: April 24, 2026, 4:30 p.m.

4.3

CVSS3.1

CVE-2026-31956 - Xibo CMS has Preview and SavedReport IDOR via disableUserCheck without controller-level authorizati…

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the …

📅 Published: April 24, 2026, 12:16 a.m. 🔄 Last Modified: April 24, 2026, 12:16 a.m.

4.9

CVSS3.1

CVE-2026-31955 - Xibo CMS has Authenticated Server-Side Request Forgery (SSRF) in Remote DataSet Functionality

Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 4.4.1 allows users with DataSet permissions to make arbitrary HTTP requests from the CMS s…

📅 Published: April 24, 2026, 12:14 a.m. 🔄 Last Modified: April 25, 2026, 1:40 a.m.

6.4

CVSS3.1

CVE-2026-31953 - Xibo CMS has Stored XSS via Notification Body with Zero-Click Execution on Login

Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.4.1 allows an authenticated user with notification creation permissions to inject arbitrary JavaScript i…

📅 Published: April 24, 2026, 12:08 a.m. 🔄 Last Modified: April 24, 2026, 6:18 p.m.

9.3

CVSS4.0

CVE-2026-25775 - SenseLive X3050 Missing authentication for critical function

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded im…

📅 Published: April 24, 2026, 12:06 a.m. 🔄 Last Modified: April 24, 2026, 12:06 a.m.

7.6

CVSS3.1

CVE-2026-31952 - Xibo CMS API has SQL Injection via DataSet Filter Parameter

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerability in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtai…

📅 Published: April 24, 2026, 12:05 a.m. 🔄 Last Modified: April 24, 2026, 4:31 p.m.

8.7

CVSS4.0

CVE-2026-35064 - SenseLive X3050 Missing authentication for critical function

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are ex…

📅 Published: April 24, 2026, 12:04 a.m. 🔄 Last Modified: April 24, 2026, 12:04 a.m.

9.3

CVSS4.0

CVE-2026-40620 - SenseLive X3050 Missing authentication for critical function

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted mo…

📅 Published: April 24, 2026, 12:02 a.m. 🔄 Last Modified: April 24, 2026, 12:02 a.m.

8.4

CVSS4.0

CVE-2026-27841 - SenseLive X3050 Cross-Site request forgery

A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce server-side validation of request origin or implement CSRF tokens, a malicious extern…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 24, 2026, 6:18 p.m.

4.4

CVSS3.1

CVE-2026-29051 - melange has Path Traversal via .PKGINFO in --persist-lint-results

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `melange build --persist-lint-results`) constructs output file paths by joining `--out-dir` with the `a…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 24, 2026, midnight
Total resulsts: 346546
Page 30 of 34,655
« previous page » next page
Filters