CVE-2026-25509Disclosure(ci4-cms-erp / ci4ms)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, the authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. This issue has been patched in version 0.28.5.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204CWE-203

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
ci4ms

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-04: 2Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 102-04
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25509 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.… https://www.cve.org/CVERecord?id=CVE-2026-25509

    Post summary

    The text references CVE-2026-25509 linked to CI4MS but offers only a brief mention and a link to the CVE record, lacking exploitation details or mitigation information.

    00000183
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-25509 Email Enumeration Vulnerability in CI4MS Authentication Prior to 0.28.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25509

    Post summary

    The post references CVE-2026-25509 as an email enumeration flaw in CI4MS authentication, noting it is fixed in version 0.28.5.0, without providing PoC, exploit code, or evidence of active exploitation.

    0000065
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more