CVE-2026-39390General(ci4-cms-erp / ci4ms)

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using strip_tags() with an <iframe> allowlist and regex-based removal of on\w+ event handlers. However, the srcdoc attribute is not an event handler and passes all filters. An attacker with admin settings access can inject an <iframe srcdoc="..."> payload with HTML-entity-encoded JavaScript that executes in the context of the parent page when rendered to unauthenticated frontend visitors. This vulnerability is fixed in 0.31.4.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ci4ms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
ci4ms

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-08: 3Technical Details · 2026-04-08: 104-08
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-39390 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the G… https://www.cve.org/CVERecord?id=CVE-2026-39390 ----- Traducción: CVE-2026-39390 CI4… http://infoflow.cloud`

    Post summary

    The text references CVE‑2026‑39390 and provides a link to its CVE record, but offers no details on exploitation, patching, or technical aspects of the vulnerability.

    0000029
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-39390 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the G… https://www.cve.org/CVERecord?id=CVE-2026-39390

    Post summary

    The excerpt notes the existence of CVE‑2026‑39390 in a CodeIgniter-based CMS skeleton but provides no evidence of exploitation, remediation, or technical details.

    00000210
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39390 Stored Cross-Site Scripting via Iframe Srcdoc Injection in CI4MS Below 0.31.4.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39390

    Post summary

    CVE-2026-39390 is a stored XSS vulnerability in CI4MS versions below 0.31.4.0 caused by iframe srcdoc injection.

    0000031
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appci4-cms-erpci4ms---

Explore more