Stored XSS Vulnerability in CI4MS CodeIgniter CMS
CVE-2026-34559
9.1CRITICAL
What is CVE-2026-34559?
A stored cross-site scripting (XSS) vulnerability exists in CI4MS, a CodeIgniter 4-based CMS, where user-controlled input for creating or editing blog tags is not properly sanitized. This flaw allows attackers to inject malicious JavaScript into the tag name field, which is stored on the server. Consequently, this payload is rendered unsafely across public tag pages and administrative interfaces, creating a potential avenue for attacks. The issue has been resolved in version 0.31.0.0, mitigating the risk of exploitation.
Affected Version(s)
ci4ms < 0.31.0.0
