Stored Cross-Site Scripting Vulnerability in CI4MS
CVE-2026-34569

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34569?

CI4MS, a CMS built on CodeIgniter 4, is susceptible to a stored cross-site scripting vulnerability prior to version 0.31.0.0. This flaw allows attackers to input malicious JavaScript into the blog category title, which is subsequently stored on the server. The insecure rendering of this payload on public blog category pages, admin interfaces, and blog views poses significant security risks, as it can compromise user data and application integrity. The issue has been resolved in the 0.31.0.0 update, emphasizing the importance of keeping software up-to-date.

Affected Version(s)

ci4ms < 0.31.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.