CVE-2026-41201General

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via Stored DOM XSS in backup module filename field manipulated via a sql file that tampers with the file name field to contain hidden XSS payload. This issue has been patched in version 0.31.5.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-07); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-12: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-12: 105-0705-12
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure2General1
2026-05-122
General2
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-41201 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text merely announces a critical CVE‑2026‑41201 with its severity score; no exploit details or mitigation steps are provided.

    1000028
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41201-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text only provides a link to a CVE advisory with minimal detail, offering no substantive information beyond a reference.

    0000018
    210 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41201 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an … https://www.cve.org/CVERecord?id=CVE-2026-41201

    Post summary

    The passage offers minimal information—only the CVE ID, a brief mention of the software, and a link to the CVE record—without details on the vulnerability, exploitation, or remediation.

    0000099
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41201 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41201 #CVE-2026-41201 #CVE #Critical #CyberSecurity #InfoSec https://t.co/wvVPBpcooO

    Post summary

    A new critical vulnerability CVE‑2026‑41201 has been announced with a severity score of 9.1, affecting multiple products, but no further technical details, PoC, or patch information are provided.

    0000041
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41201 Stored DOM XSS Leading to Account Takeover in CI4MS 0.31.4.0 Backup Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41201

    Post summary

    The entry reports a new stored DOM XSS vulnerability (CVE-2026-41201) in CI4MS 0.31.4.0 backup module that could allow account takeover, but no PoC, exploit, or patch details are provided.

    0000043
    4.0K followersView on X

Explore more