Xibo CMS Server-Side Request Forgery Vulnerability in Library Upload Functionality

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Xibo CMS versions through 4.4.0. This vulnerability allows authenticated users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. Exploitation could lead to scanning internal infrastructure, accessing local cloud metadata endpoints (such as AWS IMDS), interacting with unauthenticated internal services, or exfiltrating data.

Impact

Exploitation of this vulnerability could allow for unauthorized HTTP requests to be made from the CMS server, potentially leading to unauthorized access or manipulation of internal resources, data exfiltration, or interaction with internal services that lack authentication.

Remediation

Users should upgrade to Xibo CMS version 4.4.1 or later, which addresses this vulnerability. For users unable to upgrade, it is recommended to revoke Library upload privileges from untrusted users.

Added: May 12, 2026, 7:11 PM
Updated: May 12, 2026, 7:11 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
4.3
remediation
8.3
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.