CVE-2026-34565General(ci4-cms-erp / ci4ms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality. Post-related data selected via the Posts section is stored server-side and rendered without proper output encoding. These stored values are later rendered unsafely within administrative dashboards and public-facing navigation menus, resulting in stored DOM-based cross-site scripting (XSS). This issue has been patched in version 0.31.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Affected systems

Products
ci4ms

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-02: 4Patch / Workaround · 2026-04-02: 2Technical Details · 2026-04-02: 204-02
Signal classification2 categories
General
250.0%
Patch
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    `CI4MS` Menu Management is susceptible to a Stored DOM #XSS vulnerability (CVE-2026-34565) allowing account takeover and privilege escalation. Investigate deployments and apply input validation/output encoding. #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-34565-ci4ms-stored-dom-xss-account-takeover

    Post summary

    The advisory discloses a stored DOM XSS vulnerability (CVE‑2026‑34565) in CI4MS Menu Management that allows account takeover and privilege escalation, and recommends applying input validation/output encoding as a mitigation.

    0000029
    6 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34565: CRITICAL] CodeIgniter 4-based CMS, CI4MS, fixed a vulnerability pre-version 0.31.0.0 involving unsanitized user input leading to stored DOM-based XSS in navigation menus. Update now!#cve,CVE-2026-34565,#cybersecurity https://cvefind.com/CVE-2026-34565

    Post summary

    The post announces a critical DOM‑based XSS vulnerability in CodeIgniter 4 CMS (CI4MS) and informs users they should update to the fixed version 0.31.0.0. No exploit code or active exploitation is reported, but the CVE fix is clearly available.

    0000030
    617 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34565 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.… https://www.cve.org/CVERecord?id=CVE-2026-34565

    Post summary

    The snippet references CVE‑2026‑34565 in the context of CI4MS, noting that the issue affects versions prior to 0.31.0, but provides no further technical or exploitation details.

    00000137
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34565 - Critical CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fa... https://www.thehackerwire.com/vulnerability/CVE-2026-34565/ https://t.co/s4PW6Llf1a

    Post summary

    The post announces CVE-2026-34565 as a critical flaw affecting CI4MS, but it provides no technical specifics, patches, or exploitation details.

    0000053
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more