PT-2026-29128 · Ci4Ms · Ci4Ms

Bugmithlegend

+1

·

Published

2026-03-30

·

Updated

2026-04-01

·

CVE-2026-34558

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CI4MS versions prior to 0.31.0.0
Description CI4MS is a CodeIgniter 4-based CMS skeleton providing a modular architecture with RBAC authorization and theme support. The application does not properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). The issue occurs due to insufficient input validation and output encoding, allowing for the injection of malicious scripts. The vulnerable functionality involves the creation and management of application methods/pages.
Recommendations Update CI4MS to version 0.31.0.0 or later.

Exploit

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-34558
GHSA-V77R-XG3P-75G7

Affected Products

Ci4Ms