Stored Cross-Site Scripting in CI4MS by CI4 CMS
CVE-2026-34571

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34571?

CI4MS, a modular CMS built on CodeIgniter 4, has revealed a Stored Cross-Site Scripting vulnerability in its backend user management feature. This flaw occurs when the application inadequately sanitizes user input before rendering it in the administrative interface. As a result, attackers can inject malicious JavaScript, leading to persistent execution when backend users visit the compromised page. Potential repercussions include session hijacking, privilege escalation, and complete administrative account takeover. Users are advised to update to version 0.31.0.0, which addresses this vulnerability.

Affected Version(s)

ci4ms < 0.31.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.