Cross-Site Scripting Vulnerability in CI4MS from CodeIgniter 4
CVE-2026-34560

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34560?

CI4MS, a content management system built on CodeIgniter 4, has a vulnerability that allows for unsafe rendering of user-controlled input in its logs interface. Versions earlier than 0.31.0.0 expose an attacker to a Blind XSS scenario, enabling the storage of malicious payloads within logs that can be executed later when viewed by an administrator. This critical flaw has been addressed in version 0.31.0.0, emphasizing the importance of regular updates to maintain application security.

Affected Version(s)

ci4ms < 0.31.0.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.