Stored Cross-Site Scripting in CI4MS by CI4 CMS
CVE-2026-34571
10CRITICAL
What is CVE-2026-34571?
CI4MS, a modular CMS built on CodeIgniter 4, has revealed a Stored Cross-Site Scripting vulnerability in its backend user management feature. This flaw occurs when the application inadequately sanitizes user input before rendering it in the administrative interface. As a result, attackers can inject malicious JavaScript, leading to persistent execution when backend users visit the compromised page. Potential repercussions include session hijacking, privilege escalation, and complete administrative account takeover. Users are advised to update to version 0.31.0.0, which addresses this vulnerability.
Affected Version(s)
ci4ms < 0.31.0.0
