CVE-2026-34571Disclosure(ci4-cms-erp / ci4ms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch ci4-cms-erp ci4ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly sanitize user-controlled input before rendering it in the administrative interface, allowing attackers to inject persistent JavaScript code. This results in automatic execution whenever backend users access the affected page, enabling session hijacking, privilege escalation, and full administrative account compromise. This issue has been patched in version 0.31.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Disclousure: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Products
ci4ms

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-02: 5Patch / Workaround · 2026-04-02: 3Technical Details · 2026-04-02: 404-02
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
Disclousure
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34571 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.… https://www.cve.org/CVERecord?id=CVE-2026-34571

    Post summary

    The post simply links to the CVE record for CVE-2026-34571 without providing any additional technical or exploitation details.

    00010139
    56.9K followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical CI4MS flaw: CVE-2026-34571 A Stored XSS issue in backend user management could enable session hijacking and admin account compromise. Update immediately. 🔗 https://vulert.com/vuln-db/CVE-2026-34571 #CyberSecurity #CI4MS #StoredXSS #Vulert https://t.co/fMnVCEw4M6

    Post summary

    The post highlights a critical stored XSS flaw (CVE-2026-34571) in CI4MS that could lead to session hijacking and admin compromise, and urges users to apply updates immediately.

    0000034
    122 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclousure

    A critical stored XSS (CVE-2026-34571) in `CI4MS` backend user management allows session hijacking and admin compromise. Restrict access and monitor `CI4MS` for vendor updates. #XSS #infosec #backend https://www.pulsepatch.io/posts/cve-2026-34571-ci4ms-stored-xss

    Post summary

    The post discloses a critical stored XSS vulnerability (CVE‑2026‑34571) in CI4MS that could lead to session hijacking and admin compromise, and recommends restricting access and monitoring vendor updates.

    0000037
    6 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34571: CRITICAL] CodeIgniter 4-based CMS skeleton CI4MS has patched a Stored Cross-Site Scripting (Stored XSS) vulnerability in backend user management. Update to version 0.31.0.0 for secure usage.#cve,CVE-2026-34571,#cybersecurity https://cvefind.com/CVE-2026-34571

    Post summary

    The post announces that CVE-2026-34571, a critical stored XSS flaw in the CodeIgniter 4 CMS skeleton CI4MS, has been patched, recommending users upgrade to version 0.31.0.0.

    0000044
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34571 - Critical CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Sit... https://www.thehackerwire.com/vulnerability/CVE-2026-34571/ https://t.co/s7ZatbZCkA

    Post summary

    The post announces CVE-2026-34571, a critical stored XSS vulnerability in CI4MS before version 0.31.0.0, without mentioning exploitation, PoC, or fixes.

    0000070
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more