CVE-2026-25510Disclosure(ci4-cms-erp / ci4ms)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote Code Execution (RCE) by leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. This issue has been patched in version 0.28.5.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-04)
  • 5 total mentions across 2 days

Affected systems

Products
ci4ms

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-03: 2Mentions · 2026-02-04: 3Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-04: 202-0302-04
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure1General1
2026-02-043
Disclosure1General1Patch1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Patch

    CI4MS is affected by a RCE vulnerability (CVE-2026-25510) via arbitrary file creation in its editor. Patching is advised. #CI4MS #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-25510-ci4ms-remote-code-execution

    Post summary

    CI4MS is vulnerable to CVE-2026-25510, a remote code execution flaw through arbitrary file creation; users are advised to apply the patch.

    0000041
    1 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25510 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.… https://www.cve.org/CVERecord?id=CVE-2026-25510

    Post summary

    The provided text only lists the CVE identifier and a brief context without details on exploitation, mitigation, or technical specifics.

    00000177
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25510 Remote Code Execution in CI4MS CMS Before Version 0.28.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25510

    Post summary

    A remote code execution flaw (CVE-2026-25510) in CI4MS CMS before version 0.28.5.0 was disclosed, with no exploit details or patch information provided.

    0000057
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-25510 - Critical CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated u... https://www.thehackerwire.com/vulnerability/CVE-2026-25510/ https://t.co/e7W8ZTXVQt

    Post summary

    The post announces a critical CVE-2026-25510 affecting CI4MS but provides no further technical details, exploit information, or remediation guidance.

    0000061
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25510: CI4MS Vulnerable to Remote Code ... CI4MS file editor grants RCE gold keys to any authenticated user with basic permissions - trivial PHP upload leads to f... https://zerodaysignal.com/vulnerability/CVE-2026-25510 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces that CI4MS is vulnerable to remote code execution via a trivial PHP upload by any authenticated user with basic permissions, linking to a zero‑day signal page for more details.

    0000070
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more