CodeIgniter 4 CMS Skeleton Vulnerability in CI4MS Product by CI4MS
CVE-2026-35035
7.2HIGH
What is CVE-2026-35035?
The CI4MS application, built on CodeIgniter 4, has a vulnerability in the System Settings – Company Information section that allows for improper sanitization of user-controlled inputs. Attackers can exploit this flaw to store malicious input in administrative configuration fields, which is later rendered without sufficient output encoding on public-facing pages, specifically the main landing page. The issue does not affect the administrative dashboard but poses a security risk on the frontend, presenting an opportunity for potential attacks. This vulnerability was rectified in version 0.31.2.0.
Affected Version(s)
ci4ms < 0.31.2.0
