CVE-2026-42558 | xibosignage xibo-cms up to 4.4.1 iFrame Sandbox cross site scripting (GHSA-6389-j56c-9fww)
A vulnerability marked as problematic has been reported in xibosignage xibo-cms up to 4.4.1. Affected by this issue is some unknown functionality of the component iFrame Sandbox Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-42558. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.