


Perceptive Security
SOC/SIEM Consultancy

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0…
Published:
31 maart 2026 om 22:00:00
Alert date:
1 april 2026 om 23:03:50
Source:
nvd.nist.gov
Web Technologies
CVE-2026-34565 affects CI4MS, a CodeIgniter 4-based CMS skeleton with modular architecture and RBAC authorization. The vulnerability stems from improper sanitization of user-controlled input when adding Posts to navigation menus through Menu Management functionality. Post-related data is stored server-side without proper output encoding and rendered unsafely in administrative dashboards and public-facing navigation menus. This results in stored DOM-based cross-site scripting (XSS) attacks. The vulnerability affects versions prior to 0.31.0.0 and has been patched in version 0.31.0.0.
Technical details
Mitigation steps:
Affected products:
CI4MS
CodeIgniter 4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34565
https://github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.0.0
https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-xgh5-w62m-8mpr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
