We recommend everyone upgrade to 2.3.17 or 3.3.5 as soon as possible. All affected CMS instances on our Cloud platform have been fully patched. For further information on each advisory please see the CVE link below.
Thanks to Noam Moshe of Claroty Research - Team82 for responsibly disclosing these vulnerabilities and allowing us time to release 2.3.17/3.3.5.
Issue #1 - Path Traversal and RCE
It is possible for a logged in user of the CMS to upload a specially constructed ZIP file which will place malicious files on the web server and achieve remote code execution.
Versions affected: 1.8.0 and later. Fixed in 2.3.17 and 3.3.5
The configuration of our Cloud platform makes this exploit significantly harder or potentially impossible to exploit.
CVE-2023-33177
Issue #2 - SQL Injection
It is possible for a logged in user of the CMS to use SQL injection to pull sensitive information from the database.
Versions affected: 1.4.0 and later. Fixed in 2.3.17 and 3.3.5
Issue #3 - SQL Injection
It is possible for a logged in user of the CMS to use SQL injection to pull sensitive information from the database.
Versions affected: 3.2.0 and later. Fixed in 3.3.5
Issue #4 - SQL Injection
It is possible for a logged in user of the CMS to use SQL injection to pull sensitive information from the database.
Versions affected: 3.2.0 and later. Fixed in 3.3.5
Issue #5 - Exposed Stack Trace
Information related to the directory structure on the server was output in an error message.
Versions affected: 3.0.0 and later. Fixed in 3.3.5
More
Read more from the blog
October 2025 Release Update
Xibo’s October 2025 release updates includes the enhancements released this month across the Xibo CMS and Xibo for Android player.
Xibo Partners with Improve Digital by Azerion to Expand DOOH Opportunities
We’re delighted to announce our latest SSP Connector integration with Improve Digital by Azerion. This partnership strengthens Azerion’s digital out-of-home (DOOH) offering while opening up new revenue and operational opportunities for Xibo customers.
Xibo on Canva: A smarter way to publish your designs
The Xibo app on Canva has had an upgrade! With Xibo’s new Canva app, it’s easier and faster than ever to create, manage, and publish your content, all in one place.
More
Read more from the blog