{"id":"CVE-2025-41089","title":"Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input","summary":"Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an elemen…","severity":"none","cwe":["CWE-79"],"published":"2025-10-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-41089","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-xibo-cms","label":"cve-coordination@incibe.es"}],"tags":["nvd","exploit-available"],"epss":0.00293,"epssPercentile":0.20045,"exploits":{"github":1,"githubRepos":["https://github.com/Marinafabregat/CVE-2025-41089"],"checkedAt":"2026-10-08T13:43:30.344Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T13:42:55.078Z","slug":"CVE-2025-41089","body":"## Overview\n\nReflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, the attacker must create a template in the 'Templates' section, then add an element that has the 'Configuration Name' field, such as the 'Clock' widget. Next, modify the 'Configuration Name' field in the left-hand section.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}