Stored Cross-Site Scripting Vulnerability in CI4MS
CVE-2026-34569
10CRITICAL
What is CVE-2026-34569?
CI4MS, a CMS built on CodeIgniter 4, is susceptible to a stored cross-site scripting vulnerability prior to version 0.31.0.0. This flaw allows attackers to input malicious JavaScript into the blog category title, which is subsequently stored on the server. The insecure rendering of this payload on public blog category pages, admin interfaces, and blog views poses significant security risks, as it can compromise user data and application integrity. The issue has been resolved in the 0.31.0.0 update, emphasizing the importance of keeping software up-to-date.
Affected Version(s)
ci4ms < 0.31.0.0
