Remote Code Execution Vulnerability in CI4MS CodeIgniter CMS
CVE-2026-41587

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41587?

The CI4MS CodeIgniter Content Management System has a vulnerability that allows authenticated backend users with theme-upload permissions to upload a specially crafted ZIP file, enabling remote code execution. This occurs due to insufficient content filtering, allowing PHP files within the ZIP to be placed directly into the public web-accessible directory. As a result, these files can be executed via HTTP requests, potentially leading to unauthorized access and system compromise. This vulnerability has been addressed in version 0.31.7.0.

Affected Version(s)

ci4ms >= 0.26.0.0, < 0.31.7.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.