Cross-Site Scripting Vulnerability in CI4MS from CodeIgniter 4
CVE-2026-34560
9.1CRITICAL
What is CVE-2026-34560?
CI4MS, a content management system built on CodeIgniter 4, has a vulnerability that allows for unsafe rendering of user-controlled input in its logs interface. Versions earlier than 0.31.0.0 expose an attacker to a Blind XSS scenario, enabling the storage of malicious payloads within logs that can be executed later when viewed by an administrator. This critical flaw has been addressed in version 0.31.0.0, emphasizing the importance of regular updates to maintain application security.
Affected Version(s)
ci4ms < 0.31.0.0
