CVE-2026-34558General(ci4-cms-erp / ci4ms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or managing application methods/pages. Multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding. These stored values are later rendered directly into administrative interfaces and global navigation components without proper encoding, resulting in Stored DOM-Based Cross-Site Scripting (XSS). This issue has been patched in version 0.31.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-30); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
ci4ms

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-30: 2Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-3003-3104-01
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-302
General1Patch1
2026-03-312
Disclosure1General1
2026-04-011
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-34558 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.… https://www.cve.org/CVERecord?id=CVE-2026-34558

    Post summary

    The post only provides a brief mention of CVE-2026-34558 with no specific vulnerability details, exploit evidence, or mitigation information.

    00020139
    57.6K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34558 - Critical CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fa... https://www.thehackerwire.com/vulnerability/CVE-2026-34558/ https://t.co/W5wXjfnhRD

    Post summary

    The tweet only announces the CVE‑2026‑34558 as critical and links to an external article, providing no technical, exploit, or mitigation details.

    0001056
    157 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34558: CRITICAL] CI4MS CMS v0.31.0.0 update resolves a Stored DOM-Based XSS vulnerability allowing attackers to inject malicious scripts via user input. Update now for enhanced cyber security.#cve,CVE-2026-34558,#cybersecurity https://cvefind.com/CVE-2026-34558

    Post summary

    CI4MS CMS v0.31.0.0 has released an update that patches the CVE‑2026‑34558 Stored DOM‑Based XSS vulnerability, urging users to apply the latest version for improved security.

    0001061
    608 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Critical vulnerability in `CI4MS Methods Management` (CVE-2026-34558) allows account takeover and privilege escalation via stored DOM XSS. Monitor vendor advisories for patches. #infosec #cybersecurity #XSS https://www.pulsepatch.io/posts/cve-2026-34558-ci4ms-stored-dom-xss-account-takeover

    Post summary

    The post announces a new CVE (CVE‑2026‑34558), details a stored DOM XSS that enables account takeover and privilege escalation, and urges readers to follow vendor advisories for patching.

    0000031
    6 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34558: CI4MS: Methods Management Full A... Stored XSS in admin panels with CVSS 9.1 means one compromised low-priv account = full domain takeover across all user ... https://zerodaysignal.com/vulnerability/CVE-2026-34558 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-34558, a stored XSS flaw with a CVSS of 9.1 that could lead to full domain takeover, but does not include a PoC, exploit, mitigation or evidence of active exploitation.

    0000067
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more