CVE-2026-34560General(ci4-cms-erp / ci4ms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application renders user-controlled input unsafely within the logs interface. If any stored XSS payload exists within logged data, it is rendered without proper output encoding. This issue becomes a Blind XSS scenario because the attacker does not see immediate execution. Instead, the payload is stored within application logs and only executes later when an administrator views the logs page. This issue has been patched in version 0.31.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-02); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
ci4ms

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-02: 3Mentions · 2026-04-03: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 104-0204-03
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-023
General2Patch1
2026-04-031
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-34560 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.… https://www.cve.org/CVERecord?id=CVE-2026-34560

    Post summary

    The text only notes that CVE-2026-34560 affects CI4MS before version 0.31.0, with no additional technical or mitigation information.

    00010131
    56.9K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A stored DOM XSS vulnerability in `CI4MS` (CVE-2026-34560) could lead to full account takeover and privilege escalation across all roles. Prioritize robust input validation and output encoding. #XSS #infosec #security https://www.pulsepatch.io/posts/cve-2026-34560-ci4ms-stored-dom-xss-account-takeover

    Post summary

    The post announces a stored DOM XSS vulnerability (CVE‑2026‑34560) in CI4MS that could lead to account takeover and privilege escalation, and recommends strengthening input validation and output encoding as mitigation.

    0000034
    10 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34560: CRITICAL] CI4MS, a CodeIgniter 4-based CMS, fixed a Blind XSS vulnerability in version 0.31.0.0. Ensure your applications are updated to address security risks. #cybersecurity#cve,CVE-2026-34560,#cybersecurity https://cvefind.com/CVE-2026-34560

    Post summary

    The message announces that CI4MS version 0.31.0.0 has patched a Blind XSS vulnerability (CVE‑2026‑34560) and urges users to update to mitigate the risk.

    0000042
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34560 - Critical CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application re... https://www.thehackerwire.com/vulnerability/CVE-2026-34560/ https://t.co/vW3FIOss4P

    Post summary

    The excerpt merely announces a critical CVE in CI4MS, without providing PoC, exploitation details, patch info, or technical specifics.

    0000056
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more