


Perceptive Security
SOC/SIEM Consultancy

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0 …
Published:
5 april 2026 om 22:00:00
Alert date:
6 april 2026 om 18:04:04
Source:
nvd.nist.gov
Web Technologies
CI4MS, a CodeIgniter 4-based CMS skeleton, contains a stored cross-site scripting vulnerability in versions prior to 0.31.2.0. The vulnerability exists in the System Settings – Company Information section where administrative configuration fields fail to properly sanitize user input. Attacker-controlled input is stored server-side and rendered without proper output encoding on public-facing pages. The vulnerability only impacts the public frontend, not the administrative dashboard. The issue has been fixed in version 0.31.2.0.
Technical details
Mitigation steps:
Affected products:
CI4MS
CodeIgniter 4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35035
https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-5ghq-42rg-769x
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
