


Perceptive Security
SOC/SIEM Consultancy

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0…
Published:
31 maart 2026 om 22:00:00
Alert date:
1 april 2026 om 23:03:50
Source:
nvd.nist.gov
Web Technologies
CI4MS, a CodeIgniter 4-based CMS skeleton, contains a stored DOM-based cross-site scripting vulnerability in versions prior to 0.31.0.0. The vulnerability occurs in the Menu Management functionality where user-controlled input is not properly sanitized when adding Pages to navigation menus. Page-related data is stored server-side and rendered without proper output encoding, allowing stored XSS payloads to execute in both administrative interfaces and public-facing navigation menus. The issue has been patched in version 0.31.0.0.
Technical details
Mitigation steps:
Affected products:
CI4MS
CodeIgniter 4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34564
https://github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.0.0
https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-g4pp-fhgf-8653
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
