CVE-2025-62369: Xibo CMS: Remote Code Execution through module templates
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 patch commits.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62369?
CVE-2025-62369 is classified as a critical vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2025-62369?
To fix CVE-2025-62369, upgrade your Xibo CMS to version 4.3.1 or later.
Who is affected by CVE-2025-62369?
CVE-2025-62369 affects all authenticated users of Xibo CMS version 4.3.0 and below.
What functionality is compromised in CVE-2025-62369?
CVE-2025-62369 compromises the Module Templating functionality in the CMS Developer menu.
Is there a workaround for CVE-2025-62369?
There is no official workaround for CVE-2025-62369, and upgrading is the recommended solution.