PT-2026-6301 · Ci4Ms · Ci4Ms

Far-Horizons

·

Published

2026-02-02

·

Updated

2026-02-04

·

CVE-2026-25509

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CI4MS versions prior to 0.28.5.0
Description CI4MS, a CodeIgniter 4-based CMS skeleton, contains a flaw in its authentication implementation that allows an unauthenticated attacker to determine if an email address is registered within the system. This is achieved by observing the application’s response during the password reset process. The affected system delivers a production-ready, modular architecture with RBAC authorization and theme support.
Recommendations Update to version 0.28.5.0 or later.

Exploit

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2026-25509
GHSA-654X-9Q7R-G966

Affected Products

Ci4Ms