Remote Code Execution Vulnerability in CI4MS CodeIgniter CMS
CVE-2026-41587
8.6HIGH
What is CVE-2026-41587?
The CI4MS CodeIgniter Content Management System has a vulnerability that allows authenticated backend users with theme-upload permissions to upload a specially crafted ZIP file, enabling remote code execution. This occurs due to insufficient content filtering, allowing PHP files within the ZIP to be placed directly into the public web-accessible directory. As a result, these files can be executed via HTTP requests, potentially leading to unauthorized access and system compromise. This vulnerability has been addressed in version 0.31.7.0.
Affected Version(s)
ci4ms >= 0.26.0.0, < 0.31.7.0
