CodeIgniter 4 CMS Skeleton Vulnerability in CI4MS Product by CI4MS
CVE-2026-35035

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35035?

The CI4MS application, built on CodeIgniter 4, has a vulnerability in the System Settings – Company Information section that allows for improper sanitization of user-controlled inputs. Attackers can exploit this flaw to store malicious input in administrative configuration fields, which is later rendered without sufficient output encoding on public-facing pages, specifically the main landing page. The issue does not affect the administrative dashboard but poses a security risk on the frontend, presenting an opportunity for potential attacks. This vulnerability was rectified in version 0.31.2.0.

Affected Version(s)

ci4ms < 0.31.2.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.